CVE-2024-44843
CVSS 3.1 Score 5.9 of 10 (medium)
Details
Published Apr 15, 2025
Updated: Apr 25, 2025
CWE ID 287
Summary
CVE-2024-44843 is a vulnerability affecting the web socket handshake process in SteVe v3.7.1. Attackers can exploit this issue to bypass authentication and execute arbitrary commands by supplying crafted Open Charge Point Protocol (OCPP) requests during the handshake process. Successful exploitation may lead to unauthorized access and potential data compromise or system manipulation. Users are advised to update to the latest version of SteVe to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.