CVE-2024-21550
Estado: AnalizadaMedia (6.1)—
SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
- CWE-79
Referencias
- https://github.com/steve-community/steve/blob/steve-3.6.0/src/main/java/de/rwth/idsg/steve/config/WebSocketConfiguration.java#L69
- https://github.com/steve-community/steve/commit/a79983f843c37705182c8f54eba060c1dce3b6d1
- https://github.com/steve-community/steve/issues/1526
- https://github.com/steve-community/steve/pull/1527
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-21550",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-21550",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-12T15:19:51.512513Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "SteVe",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "3.5.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.6.0",
"lessThan": "3.6.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "3.7.0",
"lessThan": "3.7.1",
"versionType": "semver"
}
]
}
]
}
],
"published": "2024-08-12T15:15:19.903",
"references": [
{
"url": "https://github.com/steve-community/steve/blob/steve-3.6.0/src/main/java/de/rwth/idsg/steve/config/WebSocketConfiguration.java#L69",
"tags": [
"Product"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/steve-community/steve/commit/a79983f843c37705182c8f54eba060c1dce3b6d1",
"tags": [
"Patch"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/steve-community/steve/issues/1526",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/steve-community/steve/pull/1527",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "report@snyk.io"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "report@snyk.io",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface."
},
{
"lang": "es",
"value": "SteVe es una plataforma abierta que implementa diferentes versiones del protocolo OCPP para puntos de recarga de Vehículos Eléctricos, actuando como servidor central para la gestión de los puntos de recarga registrados. Los atacantes pueden inyectar código HTML y Javascript arbitrario a través de WebSockets, lo que genera cross site scripting persistentes en la interfaz de administración de SteVe."
}
],
"lastModified": "2026-06-17T07:09:43.510",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:steve-community:steve:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA3142CE-5549-4BED-8B4C-01ECF77B9E0F",
"versionEndIncluding": "3.5.1"
},
{
"criteria": "cpe:2.3:a:steve-community:steve:3.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B06144DB-7930-43A5-AE02-5EDD78BFB77F"
},
{
"criteria": "cpe:2.3:a:steve-community:steve:3.7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB0DE67E-BEEB-4123-B63B-806BED05B080"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}