CVE-2026-97212
Received Received - Intake

Predictable Session Identifier in EV Charging Station Backend

Vulnerability report for CVE-2026-97212, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: ICS-CERT

Description

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend with valid session requests.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the WebSocket backend using predictable session identifiers based on charging station IDs. Multiple endpoints can connect using the same session identifier, allowing unauthorized users to impersonate others or cause a denial-of-service by flooding the backend with valid session requests.

Detection Guidance

This vulnerability involves predictable WebSocket session identifiers that may allow unauthorized access or denial-of-service. Detection requires monitoring for multiple connections using the same session ID or unusual session ID patterns. Check WebSocket server logs for repeated session IDs, analyze network traffic for abnormal session establishment patterns, and inspect authentication logs for unexpected user sessions. No specific commands are provided in the context.

Impact Analysis

It may allow attackers to authenticate as other users, gaining unauthorized access to sensitive data or systems. Additionally, it could enable denial-of-service attacks by overwhelming the backend with excessive session requests.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to unauthorized access risks and session hijacking. Predictable session identifiers may allow attackers to impersonate users, leading to unauthorized data access or modification. This could result in breaches of confidentiality and integrity requirements under these regulations.

Mitigation Strategies

Implement unpredictable session identifiers to prevent session hijacking or DoS attacks. Ensure session identifiers are generated using cryptographically secure methods and enforce unique endpoint associations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-97212. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart