CVE-2023-49957
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors. NOTE: the vendor's perspective is "Imagine you've got two cars in your family and want to charge both in parallel on the same account/token? Why should that be rejected?"
Se descubrió un problema en Dalmann OCPP.Core anterior a 1.3.0 para OCPP (Protocolo de punto de carga abierto) para vehículos eléctricos. Permite múltiples transacciones con el mismo conectorId e idTag, contrario al estado ConcurrentTx esperado. Esto podría dar lugar a errores críticos de facturación y gestión de transacciones. NOTA: la perspectiva del proveedor es "¿Imagina que tienes dos autos en tu familia y quieres cargar ambos en paralelo en la misma cuenta/token? ¿Por qué debería rechazarse?"
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-12-03 CVE Reserved
- 2023-12-07 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/dallmann-consulting/OCPP.Core/issues/35 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dallmann-consulting Search vendor "Dallmann-consulting" | Open Charge Point Protocol Search vendor "Dallmann-consulting" for product "Open Charge Point Protocol" | < 1.3.0 Search vendor "Dallmann-consulting" for product "Open Charge Point Protocol" and version " < 1.3.0" | - |
Affected
|