Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2026-42952
Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a Denial-of-Service attack.
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:36.
Leverancier
Hydro-Québec
Product
Le Circuit Electrique charging station backend
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a Denial-of-Service attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack vector
NETWORK
Privileges required
NONE
User interaction
NONE
Vertrouwelijkheid
Geen
Integriteit
Geen
Beschikbaarheid
Geen
Beperkte impact op beschikbaarheid; risico ligt vooral bij vertrouwelijkheid of integriteit van procesdata.
Geen sterke energiesector-specifieke signalen herkend; algemene OT/ICS-relevantie.
Hydro-Québec has updated the majority of charging stations to disable OCPP, mitigating the risk of exploitation. Hydro-Québec has also implemented authentication systems to mitigate the issue for certain charging stations which are still reliant on OCPP. Contact Hydro-Québec with any additional questions.
IACS Radar-duiding
Classificatie is voorlopig; handmatige verificatie door een OT-securityanalist wordt aanbevolen.
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.