Impact
Monta's WebSocket API fails to impose limits on authentication attempts, allowing an attacker to repeatedly request credentials. This oversight can be leveraged for brute‑force attacks to gain unauthorized access or for denial‑of‑service by exhausting server resources. The weakness is typified by CWE-307, improper restriction of authentication attempts, and directly compromises confidentiality and availability of the system.
Affected Systems
The vulnerability affects Monta’s monta.app platform, specifically the WebSocket service used by operations that rely on the OCPP 1.6 Security Profile 2. No version information is provided, so all deployed instances should be evaluated.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and although the EPSS score is not available, the lack of rate limiting combined with open WebSocket endpoints suggests a plausible exploitation path. The attack vector is inferred to be network‑based WebSocket connections to the Monta application. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment