International Standards Organization ISO 15118-2 Improper Restriction of Communication Channel to Intended Endpoints
Vulnerability Description
By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker can stage a man-in-the-middle attack between an electric vehicle and chargers that comply with the ISO 15118-2 part. This vulnerability may be exploitable wirelessly, within close proximity, via electromagnetic induction.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12357
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Mark I. Johnson of Southwest Research Institute reported this vulnerability to CISA.
- Sébastien Dudek of Penthertz disclosed this vulnerability publicly.
- Jean-Christophe Delaunay and Vincent Fargues of Synacktiv disclosed this vulnerability publicly.
Affected Vendor
ISO 15118-2 Network and Application Protocol Requirements
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.