Impact
The vulnerability is the absence of throttling for repeated authentication exhaust backend resources and trigger a denial‑of‑service. The flaw is identified as CWE‑307.
Affected Systems
The affected system comprises Hydro‑Québec’s Le Circuit Electrique charging station backend. Specific firmware versions are not disclosed; the issue was observed on stations prior to Hydro‑Québec’s recent updates that disabled OCPP. The backend lacks throttling for repeated authentication attempts, permitting an attacker to exhaust system resources flaw is identified as CWE‑307 and means a successful adversary could render the station inoperable, disrupting charging services and potentially affecting many users.
Risk and Exploitability
The CVSS score of 8.7. The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an adversary sending repeated authentication requests over the OCPP connection or a similar network channel to the backend, exhausting resources and triggering a denial‑of‑service. The patch implemented by Hydro‑Québec—disabling OCPP or adding authentication safeguards—removes the primary exploitation path.
OpenCVE Enrichment