Back to Database
Status published
Critical
CVE-2024-37310
EVerest has an integer overflow in the "v2g_incoming_v2gtp" function
Vulnerability Description
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-37310
Credits & Attribution
No credits recorded in the NVD database.
References
More from EVerest
View All →CVE-2025-68141
EVerest vulnerable to null pointer dereference during DC_ChargeLoopRes document deserialization
High
7.4
CVE-2025-68140
EVerest allows null session ID to bypass session ID verification
Medium
4.3
CVE-2025-68139
In EVerest, by default, the EV is responsible for closing the connection if the module encounters an error during request processing
Medium
4.3
CVE-2025-68138
EVerest affected by memory exhaustion in libocpp
Medium
4.7
CVE-2025-68137
EVerest's Integer Overflow and Signed to Unsigned conversion lead to either stack buffer overflow or infinite loop
High
8.4
Affected Vendor
EVerest
View all reports →Affected Software
everest-core
Vulnerable Versions:
< 2024.3.1, >= 2024.4.0, < 2024.6.0
Timeline
Official Publish:
July 10th, 2024
Last Modified:
December 16th, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H