threat-intel
EVoke Systems Charging Station Management System
High
Summary
This advisory details a vulnerability in the EVoke Systems Charging Station Management System (CSMS) due to a lack of proper authentication mechanisms in its WebSocket endpoints. Attackers could exploit this to gain unauthorized administrative control over charging stations, potentially disrupting services or accessing sensitive data. The issue is exacerbated by legacy chargers using outdated security profiles, requiring EVoke to implement mitigation strategies like connection rate limiting and allow-listing.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data