VYPR
Vendor

Steve Community

Products
2
CVEs
5
Across products
5
Status
Private

Products

2

Recent CVEs

5
  • CVE-2024-25407HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions.

  • CVE-2023-52096HigDec 26, 2023
    risk 0.49cvss 7.5epss 0.01

    SteVe Community ocpp-jaxb before 0.0.8 generates invalid timestamps such as ones with month 00 in certain situations (such as when an application receives a StartTransaction Open Charge Point Protocol message with a timestamp parameter of 1000000). This may lead to a SQL…

  • CVE-2024-44843MedApr 15, 2025
    risk 0.38cvss 5.9epss 0.00

    An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

  • CVE-2026-28230MedFeb 26, 2026
    risk 0.34cvss 6.3epss 0.00

    SteVe is an open-source EV charging station management system. In versions up to and including 3.11.0, when a charger sends a StopTransaction message, SteVe looks up the transaction solely by transactionId (a sequential integer starting from 1) without verifying that the…

  • CVE-2024-21550MedAug 12, 2024
    risk 0.00cvss 6.1epss 0.00

    SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to…