CVE-2024-21550: Steve-Community Steve

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

SteVe is an open platform that implements different version of the OCPP protocol for Electric Vehicle charge points, acting as a central server for management of registered charge points. Attackers can inject arbitrary HTML and Javascript code via WebSockets leading to persistent Cross-Site Scripting in the SteVe management interface.

Affected products

  • Steve-Community Steve: up to and including 3.5.1; version 3.6.0 only; version 3.7.0 only

Published 2024-08-12. Last modified 2026-06-17.