CVE-2024-44843: Steve-Community Steve

Medium severity, CVSS 5.9. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests.

Affected products

Published 2025-04-15. Last modified 2026-06-17.