Subscriptions
No data.
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 26 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | EVerest is an EV charging software stack. Prior to versions to 2026.02.0, ISO15118_chargerImpl::handle_update_energy_transfer_modes copies a variable-length list into a fixed-size array of length 6 without bounds checking. With schema validation disabled by default, oversized MQTT Cmd payloads can trigger out-of-bounds writes and corrupt adjacent EVSE state or crash the process. Version 2026.02.0 contains a patch. | |
| Title | EVerest's ISO15118 update_energy_transfer_modes overflow can corrupt EVSE state | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-26T18:24:18.212Z
Reserved: 2026-02-24T02:32:39.798Z
Link: CVE-2026-27816
Updated: 2026-03-26T17:48:34.319Z
Status : Received
Published: 2026-03-26T17:16:34.210
Modified: 2026-03-26T17:16:34.210
Link: CVE-2026-27816
No data.
OpenCVE Enrichment
No data.