Thales OCPP v1.6 Unauthenticated Information Disclosure Vulnerability
Vulnerability
A vulnerability exists in Thales chargers that use the Open Charge Point Protocol (OCPP) version 1.6). The issue arises because service interactions can be performed without authentication, allowing an attacker with some knowledge of the protocol to obtain information about the charger.
Impact
Exploitation of this vulnerability could lead to unauthorized information disclosure regarding the charger.
Added: Jan 7, 2026, 7:13 PM
Updated: Jan 7, 2026, 7:13 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.6exploitability
7.4remediation
0.0relevance
1.9threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
