CVE-2026-44383 Details
Description
Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.
A vulnerability exists in the Hydro-Québec Le Circuit Électrique charging station backend, allowing multiple connections using the same charging station ID. This could enable an attacker to deploy several instances of malicious OCPP clients to overwhelm the backend. The vulnerability is categorized under CWE-613: Insufficient Session Expiration.
Hydro-Québec has updated most charging stations to disable OCPP, mitigating the risk of exploitation. For stations that still rely on OCPP, authentication systems have been implemented to address the issue. Contact Hydro-Québec for further inquiries.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-188-01.json | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-188-01 | [email protected] | AdvisoryBundleRemedy |
| https://www.hydroquebec.com/nous-joindre/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hydro-Québec Le Circuit Electrique | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 13, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion