CVE-2024-44843: Medium severity steve vulnerability
Published Apr 15, 2025
·Updated
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
Affected Software
2 affected components
SteVe SteVe
Steve-community Steve=3.7.1
Event History
Apr 15, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44843?
CVE-2024-44843 is classified as a critical vulnerability due to its ability to allow attackers to bypass authentication and execute arbitrary commands.
2
How do I fix CVE-2024-44843?
To fix CVE-2024-44843, upgrade SteVe to version 3.7.2 or later, which includes a patch for this vulnerability.
3
What type of attack does CVE-2024-44843 facilitate?
CVE-2024-44843 facilitates authentication bypass attacks through crafted OCPP requests.
4
Which versions of SteVe are affected by CVE-2024-44843?
CVE-2024-44843 affects SteVe version 3.7.1 specifically.
5
Is CVE-2024-44843 easy to exploit?
Yes, CVE-2024-44843 is relatively easy to exploit due to the nature of the web socket handshake vulnerability.