← Retour
CVE-2026-44098
high
CVSS 8.6
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
Résumé
This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-44098** a été découverte dans command-injection.
Risque d'opérations non autorisées ou de divulgation. Score CVSS : 8.6/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « command-injection CVE-2026-44098 » sur le site de l'éditeur.
CVE-2026-44098 (command-injection) — CWE-78 / CVSS v3 8.6
Vecteur d'attaque : distant (réseau) / non authentifié / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
認証されていないリモート攻撃者がファイアウォールをバイパスしてOSコマンドインジェクションを行うことができます。
📍 Périmètre concerné
OCPPバックエンドのシステム
🔥 Gravité
高い重要度。任意のOSコマンドが実行されることで重大な影響を与える可能性があります。
🔧 Comment corriger
OCPPバックエンドの管理方法を見直し、ファイアウォール設定とインジェクション防止策を強化してください。
🛡️ Contournement
ファイアウォール規則を強化し、信頼できる接続のみを許可すること。
🔍 Détection
ファイアウォールバイパスや異常なコマンド実行のログを監視し、関連のシステムアクティビティを確認してください。