An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors. NOTE: the vendor's perspective is "Imagine you've got two cars in your family and want to charge both in parallel on the same account/token? Why should that be rejected?"
References
Link | Resource |
---|---|
https://github.com/dallmann-consulting/OCPP.Core/issues/35 | Exploit Issue Tracking Vendor Advisory |
Configurations
History
13 Dec 2023, 15:14
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:dallmann-consulting:open_charge_point_protocol:*:*:*:*:*:*:*:* | |
References | () https://github.com/dallmann-consulting/OCPP.Core/issues/35 - Exploit, Issue Tracking, Vendor Advisory |
07 Dec 2023, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-07 13:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-49957
Mitre link : CVE-2023-49957
CVE.ORG link : CVE-2023-49957
JSON object : View
Products Affected
dallmann-consulting
- open_charge_point_protocol
CWE