A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption. | |
Weaknesses | CWE-120 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: siemens
Published: 2025-02-11T10:29:18.342Z
Updated: 2025-02-12T20:51:43.499Z
Reserved: 2025-01-29T11:11:04.381Z
Link: CVE-2025-24956

Updated: 2025-02-12T20:46:50.990Z

Status : Received
Published: 2025-02-11T11:15:17.273
Modified: 2025-02-11T11:15:17.273
Link: CVE-2025-24956

No data.