As cited
Copy frozen at (site build).
vulnerabilities
EVoke Systems Charging Station Management System
EVoke Systems Charging Station Management System contains multiple critical vulnerabilities across all versions, including missing authentication on WebSocket endpoints (CVSS 9.4), improper rate limiting, and insufficient session management that could allow attackers to impersonate charging stations or disrupt services. The vulnerabilities affect energy and transportation infrastructure globally, though they stem primarily from the need to support legacy chargers with outdated security profiles. EVoke is implementing server-side mitigations including allow-listing, session monitoring, connection rate limiting, and working with manufacturers to upgrade devices to stronger security profiles.
Why it matters: Critical infrastructure charging systems are exposed to unauthorized administrative access and denial-of-service; operators should immediately review EVoke deployments and implement the vendor's recommended server-side protections while planning legacy charger upgrades.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
EVoke Systems Charging Station Management System
EVoke Systems Charging Station Management System contains multiple critical vulnerabilities across all versions, including missing authentication on WebSocket endpoints (CVSS 9.4), improper rate limiting, and insufficient session management that could allow attackers to impersonate charging stations or disrupt services. The vulnerabilities affect energy and transportation infrastructure globally, though they stem primarily from the need to support legacy chargers with outdated security profiles. EVoke is implementing server-side mitigations including allow-listing, session monitoring, connection rate limiting, and working with manufacturers to upgrade devices to stronger security profiles.
Why it matters: Critical infrastructure charging systems are exposed to unauthorized administrative access and denial-of-service; operators should immediately review EVoke deployments and implement the vendor's recommended server-side protections while planning legacy charger upgrades.
- Source published
- First seen by Cybersecurity Tracker