{"id":"CVE-2023-49955","details":"An issue was discovered in Dalmann OCPP.Core before 1.2.0 for OCPP (Open Charge Point Protocol) for electric vehicles. It does not validate the length of the chargePointVendor field in a BootNotification message, potentially leading to server instability and a denial of service when processing excessively large inputs. NOTE: the vendor's perspective is \"OCPP.Core is intended for use in a protected environment/network.\"","modified":"2026-08-12T03:51:11.883158735Z","published":"2023-12-07T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49955.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49955.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49955"},{"type":"REPORT","url":"https://github.com/dallmann-consulting/OCPP.Core/issues/32"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dallmann-consulting/ocpp.core","events":[{"introduced":"0"},{"fixed":"7d1d59090aa895043b28f0c5b14212c3e69a39cf"}],"database_specific":{"cpe":"cpe:2.3:a:dallmann-consulting:open_charge_point_protocol:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"OCPP.Core"},{"fixed":"1.2.0"},{"introduced":"0"}],"source":["DESCRIPTION","CPE_RANGE"]}}],"versions":["V1.1.0","0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49955.json"}}],"schema_version":"1.9.0"}