Description
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
Published: 2026-10-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized Access
Action: Apply Mitigation
AI Analysis

Impact

Monta's WebSocket API fails to impose limits on authentication attempts, allowing an attacker to repeatedly request credentials. This oversight can be leveraged for brute‑force attacks to gain unauthorized access or for denial‑of‑service by exhausting server resources. The weakness is typified by CWE-307, improper restriction of authentication attempts, and directly compromises confidentiality and availability of the system.

Affected Systems

The vulnerability affects Monta’s monta.app platform, specifically the WebSocket service used by operations that rely on the OCPP 1.6 Security Profile 2. No version information is provided, so all deployed instances should be evaluated.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, and although the EPSS score is not available, the lack of rate limiting combined with open WebSocket endpoints suggests a plausible exploitation path. The attack vector is inferred to be network‑based WebSocket connections to the Monta application. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on October 2, 2026 at 23:24 UTC.

Remediation

Vendor Workaround

Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it.


OpenCVE Recommended Actions

  • Adopt Monta’s official recommendation to enforce authenticated WebSocket connections and deprecate unauthenticated access on a rolling basis, enabling OCPP 1.6 Security Profile 2.
  • Enable Monta’s built‑in rate limiting and automated connection throttling at the WebSocket layer to automatically identify and block abusive patterns such as rapid reconnection, ID brute‑forcing, or excessive command volume.
  • Configure network firewalls or reverse proxies to throttle or block repeated connection attempts to the Monta WebSocket endpoint.
  • Ensure duplicate connection attempts are managed per the OCPP specification, where a new authenticated connection supersedes an existing session for the same station ID.

Generated by OpenCVE AI on October 2, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Description The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
Title Monta monta.app Improper Restriction of Excessive Authentication Attempts
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-10-02T21:32:30.615Z

Reserved: 2026-09-24T16:22:04.109Z

Link: CVE-2026-97363

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T22:16:56.910

Modified: 2026-10-02T22:16:56.910

Link: CVE-2026-97363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T23:30:10Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts