CVE-2024-44843

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 25, 2025
CWE ID 287

Summary

CVE-2024-44843 is a vulnerability affecting the web socket handshake process in SteVe v3.7.1. Attackers can exploit this issue to bypass authentication and execute arbitrary commands by supplying crafted Open Charge Point Protocol (OCPP) requests during the handshake process. Successful exploitation may lead to unauthorized access and potential data compromise or system manipulation. Users are advised to update to the latest version of SteVe to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share