Vulnerabilities (CVE)

Filtered by vendor Steve-community Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-44843 1 Steve-community 1 Steve 2025-04-25 N/A 5.9 MEDIUM
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
CVE-2024-25407 1 Steve-community 1 Steve 2025-04-25 N/A 7.5 HIGH
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.
CVE-2023-52096 1 Steve-community 1 Ocpp-jaxb 2024-11-21 N/A 7.5 HIGH
SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL exception in applications, and may undermine the integrity of transaction records.
CVE-2024-21550 1 Steve-community 1 Steve 2024-08-13 N/A 6.1 MEDIUM
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.