Description
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- EVerest / everest-core< 2024.3.1 – < 2024.3.1
- EVerest / everest-core>= 2024.4.0, < 2024.6.0 – >= 2024.4.0, < 2024.6.0
References
- VENDOR_ADVISORYhttps://github.com/EVerest/everest-core/security/advisories/GHSA-8g9q-7qr9-vc96
- PATCHhttps://github.com/EVerest/everest-core/commit/f73620c4c0f626e1097068a47e10cc27b369ad8e
- PATCHhttps://github.com/EVerest/everest-core/releases/tag/2024.3.1
- PATCHhttps://github.com/EVerest/everest-core/releases/tag/2024.6.0
Updated 6m ago · 8 sources