CVE Vulnerabilities

CVE-2024-44843

Improper Authentication

Published: Apr 15, 2025 | Modified: Apr 25, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Steve Steve-community 3.7.1 (including) 3.7.1 (including)

Potential Mitigations

References