CVE-2023-49958

HIGH

Dallmann-consulting Open Charge Point... - Improper Input Validation

Title source: rule
STIX 2.1

Description

An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. The server processes mishandle StartTransaction messages containing additional, arbitrary properties, or duplicate properties. The last occurrence of a duplicate property is accepted. This could be exploited to alter transaction records or impact system integrity.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Vendor Advisory
https://github.com/dallmann-consulting/OCPP.Core/issues/36

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 42.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (1)
dallmann-consulting/open_charge_point_protocol < 1.2.0
Published Dec 07, 2023
Tracked Since Feb 18, 2026