CVE 8.3 HIGH

International Standards Organization ISO 15118-2 Improper Restriction of Communication Channel to Intended Endpoints_CVE-2025-12357

8.3 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H

Description

By manipulating the Signal Level Attenuation Characterization (SLAC)
protocol with spoofed measurements, an attacker can stage a
man-in-the-middle attack between an electric vehicle and chargers that
comply with the ISO 15118-2 part. This vulnerability may be exploitable
wirelessly, within close proximity, via electromagnetic induction.

Basic Information

ID CVE-2025-12357
Source icscert
Published Oct 31, 2025 at 15:33

Affected Product

Vendor ISO 15118-2 Network and Application Protocol Requirements
Product EV Car Chargers
Version Part 15118-2 Network and Application Protocol Requirements
Affected Versions ISO 15118-2 Network and Application Protocol Requirements EV Car Chargers Part 15118-2 Network and Application Protocol Requirements

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.