Cloudcharge
cloudcharge
4 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session ide...Show more |
1Cloudcharge 1Cloudcharge.se Jun 17, 2026 Feb 27, 2026 8.7 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks by suppressing or m...Show more |
1Cloudcharge 1Cloudcharge.se Jun 17, 2026 Feb 27, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersonation and manipulate data sent to the backend. An unauthenticated attacker can connect to the OCPP...Show more |
1Cloudcharge 1Cloudcharge.se Jun 17, 2026 Feb 27, 2026 6.9 MEDIUM· v4 5.3 MEDIUM· v3 N/A· v2 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. |