2026-07-08NOTABLECISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend, a transferable lesson for any charge-point operator
Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01
cve · CVE-2026-42952 single-source-national-cert
Coverage
1
first 2026-07-08 → last 2026-07-08
Latest activity
2026-07-08
CISA ICSA-26-188-01: unauthenticated OCPP WebSocket in an EV-charging backend, a transferable lesson for any…
Peak priority
notable
1 notable
Targets
energy
sectors: energy, transport
Sources cited
2
2 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-42952, newest first. Check the date before acting on an older one.
- Any OCPP central-system operator: verify the WebSocket upgrade enforces mutual TLS or HTTP Basic Auth per OCPP Security Profile 2/3 rather than accepting unauthenticated ws:// upgrades.2026-07-08CVE-2026-20744 +2
- Rate-limit repeated OCPP BootNotification/Authorize attempts per source, and reject duplicate concurrent connections claiming the same ChargePointId (closes the session-exhaustion class); since charge-point hardware carries no endpoint agent, detect on backend session-churn/connection-count anomalies per charge-point ID.2026-07-08CVE-2026-20744 +2
Defender insights
What each entry about CVE-2026-42952 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (1 across 1 tactic)
1 technique observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-08/cve-2026-20744-hydro-quebec-ocpp-unauth-websocket · ATT&CK page ↗
Entries about Hydro-Quebec EV-charging: no auth-attempt throttling -> DoS (CVSS 7.5), ICSA-26-188-01 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Hydro-Quebec EV-charging OCPP WebSocket unauthenticated access -> privilege escalation (CVSS 9.8), CISA ICSA-26-188-01×1
- Hydro-Quebec EV-charging: duplicate concurrent sessions per charge-point ID -> DoS (CVSS 7.5), ICSA-26-188-01×1
Where this entity is cited
Source distribution
- cisa.gov1 (50%)
- raw.githubusercontent.com1 (50%)