Impact
The vulnerability is the absence of throttling on repeated authentication attempts to Hydro‑Québec’s Le Circuit Electrique charging station backend, allowing an attacker to consume resources and trigger a denial‑of‑service, consistent with the identified CWE‑307.
Affected Systems
It affects Hydro‑Québec’s Le Circuit Electrique charging station backend. Specific firmware or hardware revisions are not disclosed, but Hydro‑Québec has released updates for most stations that disable OCPP or add authentication safeguards.
Risk and Exploitability
The CVSS score is 8.7, the EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog. The lack of throttling permits repeated authentication attempts over the OCPP interface or another network channel, potentially exhausting backend resources. Hydro‑Québec’s official solution—disabling OCPP or implementing authentication controls—removes the main exploitation path.
OpenCVE Enrichment