Impact
Hydro‑Québec’s Le Circuit Electrique charging station backend allows multiple concurrent connections that share the same charging‑station ID, a weakness classified as CWE‑613. An attacker can repeatedly connect to the OCPP interface using the same spoofed station ID, potentially flooding the backend with malicious client sessions and degrading or blocking normal operation. This can lead to a denial‑of‑service for legitimate charging traffic.
Affected Systems
The backend server of all Le Circuit Electrique charging stations that still expose OCPP is affected. This includes every station that has not yet received the firmware update that disables OCPP or has not yet deployed the new authentication mechanism implemented by Hydro‑Québec.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. A low EPSS score of <1% suggests limited current exploitation, and the vulnerability is not listed in CISA KEV gateway or backend can leverage the lack of session expiration to repeatedly establish forged connections, potentially overwhelming backend resources. The CNA remediation—disabling OCPP or adding authentication—removes the attack surface and eliminates the denial‑of‑service risk.
OpenCVE Enrichment