CVE-2025-12357

By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within close proximity, via electromagnetic induction.
Configurations

No configuration.

History

31 Oct 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-31 16:15

Updated : 2025-10-31 16:15


NVD link : CVE-2025-12357

Mitre link : CVE-2025-12357

CVE.ORG link : CVE-2025-12357


JSON object : View

Products Affected

No product.

CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints