CVE-2023-49958 affects Dalmann OCPP.Core through version 1.2.0, allowing an attacker to manipulate StartTransaction messages in the Open Charge Point Protocol (OCPP) by injecting additional or duplicate properties. This vulnerability, rated 7.5 HIGH, could lead to altered transaction records or impact system integrity due to the server accepting the last occurrence of a duplicate property. While no active exploitation, public exploit code, or significant community discussion has been observed, the direct network attack vector and low attack complexity make it a notable concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.0CPE matchmatch criteria | cpe:2.3:a:dallmann-consulting:open_charge_point_protocol:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.