CVE-2025-24956

Name
CVE-2025-24956
Description
A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a length check when parsing X509 serial numbers. Thus, an attacker could introduce a buffer overflow that leads to memory corruption.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
productcert@siemens.com https://cert-portal.siemens.com/productcert/html/ssa-647005.html

Match rules

CPE URI Source package Min version Max version
openv2g >= 0 < V0.9.6
cpe:2.3:a:siemens:openv2g:*:*:*:*:*:*:*:* openv2g >= None < 0.9.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
openv2g edge-community 0.9.5-r0 Olliver Schinagl <oliver@schinagl.nl> possibly vulnerable
openv2g 3.22-community 0.9.5-r0 Olliver Schinagl <oliver@schinagl.nl> possibly vulnerable