Siemens OpenV2G
cpe:2.3:a:siemens:openv2g:*:*:*:*:*:*:*
- < 0.9.6
A buffer overflow vulnerability has been identified in OpenV2G versions prior to 0.9.6. The issue arises in the EXI parsing feature, which lacks a proper length check when handling X509 serial numbers. This oversight allows an attacker to exploit the vulnerability, potentially causing memory corruption.
Exploitation of this vulnerability can lead to memory corruption, which may be leveraged to execute arbitrary code or cause a denial-of-service condition.
Users are advised to update OpenV2G to version 0.9.6 or later. The latest version can be downloaded from the OpenV2G SourceForge release page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.