CyberRota Analysis
AI-GeneratedThe vulnerability affects the WebSocket backend, which improperly manages session identifiers, allowing multiple endpoints to connect using the same identifier. This flaw can lead to unauthorized access, enabling attackers to impersonate legitimate users, or potentially trigger a denial-of-service condition by flooding the backend with valid session requests. Organizations utilizing this WebSocket implementation should prioritize remediation to protect against these significant security risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.