Back to overview

CVE-2026-54479

HIGH
7.3
CVSS 3.1
Description
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

Metadata

CVE ID
CVE-2026-54479
State
PUBLISHED
Assigner
icscert
Reserved
2026-06-18 19:23 UTC
Published
2026-06-25 20:56 UTC
Last updated
2026-06-25 20:56 UTC
Primary CWE
CWE-613
CWE-613
Vendor / Product
EVoke / EVoke CSMS
Sources
cve.org  ·  NVD

Severity & Metrics

7.3 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Affected products (1)
VendorProductPlatformVersions
EVoke EVoke CSMS All versions
Weakness (CWE)
CWESourceDescription
CWE-613 cna CWE-613
CVSS scores (2)
ScoreSeverityVersionSourceVector
7.3 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
6.9 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Back to overview