WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

Monta.app

Analyst seen from behind facing a wall of blurred monitoring screensAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

Given that no authentication is required, this can lead to privilege escalation (gaining powers on a system that the user was not given) and potentially compromise the security of the entire system. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS (the encryption that secures a connection to a website)) and encourage operators to enable it.

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis.

Sources & evidence