« Volver al listado

CVE-2024-37310

Estado: AplazadaCrítica (9)—

EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-37310",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-37310",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-07-11T14:40:06.465515Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 9,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "EVerest",
          "product": "everest-core",
          "versions": [
            {
              "status": "affected",
              "version": "< 2024.3.1"
            },
            {
              "status": "affected",
              "version": ">= 2024.4.0, < 2024.6.0"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:everest:everest-core:*:*:*:*:*:*:*:*"
          ],
          "vendor": "everest",
          "product": "everest-core",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "2024.6.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-07-10T20:15:03.790",
  "references": [
    {
      "url": "https://github.com/EVerest/everest-core/commit/f73620c4c0f626e1097068a47e10cc27b369ad8e",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/EVerest/everest-core/releases/tag/2024.3.1",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/EVerest/everest-core/releases/tag/2024.6.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/EVerest/everest-core/security/advisories/GHSA-8g9q-7qr9-vc96",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/EVerest/everest-core/commit/f73620c4c0f626e1097068a47e10cc27b369ad8e",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/EVerest/everest-core/releases/tag/2024.3.1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/EVerest/everest-core/releases/tag/2024.6.0",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/EVerest/everest-core/security/advisories/GHSA-8g9q-7qr9-vc96",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://plaxidityx.com/blog/automotive-cyber-security/ev-cyber-security-plaxidityx-discovers-critical-vulnerability-in-everest-open-source-ev-charging-firmware-stack-cve-2024-37310/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        },
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "EVerest is an EV charging software stack. An integer overflow in the \"v2g_incoming_v2gtp\" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0."
    },
    {
      "lang": "es",
      "value": "EVerest es una pila de software de carga de vehículos eléctricos. Un desbordamiento de enteros en la función \"v2g_incoming_v2gtp\" en la implementación v2g_server.cpp puede permitir que un atacante remoto desborde el montón del proceso. Esta vulnerabilidad se solucionó en 2024.3.1 y 2024.6.0."
    }
  ],
  "lastModified": "2026-06-17T07:38:07.097",
  "sourceIdentifier": "security-advisories@github.com"
}