Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:dallmann-consulting:open_charge_point_protocol:*:*:*:*:*:*:*:*", "matchCriteriaId": "C39AD5F2-CEA9-4F62-B0BA-34A433016635", "versionEndExcluding": "1.3.0", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "descriptions": [{"lang": "en", "value": "An issue was discovered in Dalmann OCPP.Core before 1.3.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It permits multiple transactions with the same connectorId and idTag, contrary to the expected ConcurrentTx status. This could result in critical transaction management and billing errors. NOTE: the vendor's perspective is \"Imagine you've got two cars in your family and want to charge both in parallel on the same account/token? Why should that be rejected?\""}, {"lang": "es", "value": "Se descubri\u00f3 un problema en Dalmann OCPP.Core anterior a 1.3.0 para OCPP (Protocolo de punto de carga abierto) para veh\u00edculos el\u00e9ctricos. Permite m\u00faltiples transacciones con el mismo conectorId e idTag, contrario al estado ConcurrentTx esperado. Esto podr\u00eda dar lugar a errores cr\u00edticos de facturaci\u00f3n y gesti\u00f3n de transacciones. NOTA: la perspectiva del proveedor es \"\u00bfImagina que tienes dos autos en tu familia y quieres cargar ambos en paralelo en la misma cuenta/token? \u00bfPor qu\u00e9 deber\u00eda rechazarse?\""}], "id": "CVE-2023-49957", "lastModified": "2024-11-21T08:34:04.867", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "NONE", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2023-12-07T13:15:07.790", "references": [{"source": "cve@mitre.org", "tags": ["Exploit", "Issue Tracking", "Vendor Advisory"], "url": "https://github.com/dallmann-consulting/OCPP.Core/issues/35"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Issue Tracking", "Vendor Advisory"], "url": "https://github.com/dallmann-consulting/OCPP.Core/issues/35"}], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "NVD-CWE-noinfo"}], "source": "nvd@nist.gov", "type": "Primary"}]}