Linuxfoundation

Everest

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 26.01.2026 22:12:47
  • Zuletzt bearbeitet 17.02.2026 20:48:01

EVerest is an EV charging software stack. In versions up to and including 2025.12.1, it is possible to bypass the sequence state verification including authentication, and send requests that transition to forbidden states relative to the current one,...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 21.01.2026 20:16:06
  • Zuletzt bearbeitet 06.02.2026 21:22:03

EVerest is an EV charging software stack. Prior to version 2025.10.0, during the deserialization of a `DC_ChargeLoopRes` message that includes Receipt as well as TaxCosts, the vector `<DetailedTax>tax_costs` in the target `Receipt` structure is acces...

  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 19:54:51
  • Zuletzt bearbeitet 06.02.2026 21:22:06

EVerest is an EV charging software stack. Prior to version 2025.9.0, once the validity of the received V2G message has been verified, it is checked whether the submitted session ID matches the registered one. However, if no session has been registere...

  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 19:36:36
  • Zuletzt bearbeitet 06.02.2026 21:22:10

EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminate_connection_on_failed_response` is `False`, which leaves the responsibility for session and connection termination to the EV. In ...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 21.01.2026 19:25:12
  • Zuletzt bearbeitet 06.02.2026 21:21:59

EVerest is an EV charging software stack. Prior to version 2025.9.0, in several places, integer values are concatenated to literal strings when throwing errors. This results in pointers arithmetic instead of printing the integer value as expected, li...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 21.01.2026 19:20:09
  • Zuletzt bearbeitet 06.02.2026 21:21:52

EVerest is an EV charging software stack. Prior to version 2025.10.0, an integer overflow occurring in `SdpPacket::parse_header()` allows the current buffer length to be set to 7 after a complete header of size 8 has been read. The remaining length t...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 21.01.2026 19:18:21
  • Zuletzt bearbeitet 06.02.2026 21:21:48

EVerest is an EV charging software stack. Prior to version 2025.10.0, once the module receives a SDP request, it creates a whole new set of objects like `Session`, `IConnection` which open new TCP socket for the ISO15118-20 communications and registe...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 21.01.2026 18:56:05
  • Zuletzt bearbeitet 06.02.2026 21:21:45

EVerest is an EV charging software stack. Prior to version 2025.10.0, C++ exceptions are not properly handled for and by the `TbdController` loop, leading to its caller and itself to silently terminates. Thus, this leads to a denial of service as it ...

  • EPSS 0.07%
  • Veröffentlicht 21.01.2026 18:32:13
  • Zuletzt bearbeitet 06.02.2026 21:21:42

EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module to crash. This is particularly critical because the manager shuts down all other modules and exits wh...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 21.01.2026 18:28:40
  • Zuletzt bearbeitet 06.02.2026 21:21:17

EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[vec.size()-1]` and `vec[vec.size()-2]` without checking that at least two bytes are present. Malformed S...