« Volver al listado

CVE-2024-21550

Estado: AnalizadaMedia (6.1)—

SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-21550",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-21550",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-12T15:19:51.512513Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "report@snyk.io",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "report@snyk.io",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "SteVe",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "3.5.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.6.0",
              "lessThan": "3.6.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "3.7.0",
              "lessThan": "3.7.1",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-08-12T15:15:19.903",
  "references": [
    {
      "url": "https://github.com/steve-community/steve/blob/steve-3.6.0/src/main/java/de/rwth/idsg/steve/config/WebSocketConfiguration.java#L69",
      "tags": [
        "Product"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://github.com/steve-community/steve/commit/a79983f843c37705182c8f54eba060c1dce3b6d1",
      "tags": [
        "Patch"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://github.com/steve-community/steve/issues/1526",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "report@snyk.io"
    },
    {
      "url": "https://github.com/steve-community/steve/pull/1527",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "report@snyk.io"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "report@snyk.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface."
    },
    {
      "lang": "es",
      "value": "SteVe es una plataforma abierta que implementa diferentes versiones del protocolo OCPP para puntos de recarga de Vehículos Eléctricos, actuando como servidor central para la gestión de los puntos de recarga registrados. Los atacantes pueden inyectar código HTML y Javascript arbitrario a través de WebSockets, lo que genera cross site scripting persistentes en la interfaz de administración de SteVe."
    }
  ],
  "lastModified": "2026-06-17T07:09:43.510",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:steve-community:steve:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA3142CE-5549-4BED-8B4C-01ECF77B9E0F",
              "versionEndIncluding": "3.5.1"
            },
            {
              "criteria": "cpe:2.3:a:steve-community:steve:3.6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B06144DB-7930-43A5-AE02-5EDD78BFB77F"
            },
            {
              "criteria": "cpe:2.3:a:steve-community:steve:3.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB0DE67E-BEEB-4123-B63B-806BED05B080"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "report@snyk.io"
}