Medium severity5.9NVD Advisory· Published Apr 15, 2025· Updated Jun 17, 2026
CVE-2024-44843
CVE-2024-44843
Description
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:steve-community:steve:3.7.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:steve-community:steve:3.7.1:*:*:*:*:*:*:*
- (no CPE)range: <3.7.1
- SteVe/SteVedescription
Patches
Vulnerability mechanics
References
3- gist.github.com/Badranh/94359664799db6d4709871f0c353f476nvdExploitThird Party Advisory
- github.com/steve-community/steve/blob/master/src/main/java/de/rwth/idsg/steve/ocpp/ws/OcppWebSocketHandshakeHandler.javanvdProduct
- github.com/steve-community/steve/issues/1546nvdIssue Tracking
News mentions
0No linked articles in our index yet.