CVE-2024-37310
CVSS V2 None
CVSS V3 None
Description
EVerest is an EV charging software stack. An integer overflow in the "v2g_incoming_v2gtp" function in the v2g_server.cpp implementation can allow a remote attacker to overflow the process' heap. This vulnerability is fixed in 2024.3.1 and 2024.6.0.
Overview
- CVE ID
- CVE-2024-37310
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-07-10T19:39:36.860Z
- Last Modified Date
- 2024-07-10T19:39:36.860Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/EVerest/everest-core/security/advisories/GHSA-8g9q-7qr9-vc96 | x_refsource_CONFIRM |
https://github.com/EVerest/everest-core/commit/f73620c4c0f626e1097068a47e10cc27b369ad8e | x_refsource_MISC |
https://github.com/EVerest/everest-core/releases/tag/2024.3.1 | x_refsource_MISC |
https://github.com/EVerest/everest-core/releases/tag/2024.6.0 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-37310 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37310 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-07-11 13:03:31 | Added to TrackCVE |