SteVe is an open platform that implements different version of...
Vulnerability Description
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21550
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Calum Hutton (Snyk Security Research)
References
- https://github.com/steve-community/steve/blob/steve-3.6.0/src/main/java/de/rwth/idsg/steve/config/WebSocketConfiguration.java#L69
- https://github.com/steve-community/steve/issues/1526
- https://github.com/steve-community/steve/pull/1527
- https://github.com/steve-community/steve/commit/a79983f843c37705182c8f54eba060c1dce3b6d1