CVE-2024-44843: Steve-Community Steve
Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.
Affected products
- Steve-Community Steve: version 3.7.1 only
Published 2025-04-15. Last modified 2026-06-17.