CVE-2022-0878 describes a vulnerability in the Combined Charging System (CCS) used for DC rapid charging in electric vehicles, affecting all implementations of the HomePlug Green PHY, DIN 70121, and ISO 15118 standards. This vulnerability allows an attacker to disrupt the critical communication between an EV and its charger, causing charging sessions to abort. The attack can be conducted wirelessly from a distance using electromagnetic interference with off-the-shelf radio hardware and minimal technical knowledge. With a CVSS score of 6.5 (MEDIUM), the attack vector is adjacent network, with low attack complexity, requiring no privileges or user interaction, and resulting in high availability impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0CPE matchmatch criteria | cpe:2.3:o:combined_charging_system_project:combined_charging_system_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.