Monta.app
What happened
Given that no authentication is required, this can lead to privilege escalation (gaining powers on a system that the user was not given) and potentially compromise the security of the entire system. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS (the encryption that secures a connection to a website)) and encourage operators to enable it.
View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis.
Sources & evidence
- CISA Advisories Primary / official
Monta monta.app ↗
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-02