Skip to content

Security1 publisher2 min readPublished

CISA says every version of Monta's charging platform lets attackers pose as EV chargers

CISA lists four CVEs in every version of Monta's EV-charging platform that let attackers pose as charging stations. Monta is phasing out unauthenticated access on a rolling basis and has not said when it will finish.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying CISA says every version of Monta's charging platform lets attackers pose as EV chargers
Generated illustration

What happened

  • CISA says exploitation could give attackers administrative control of vulnerable charging stations or let them disrupt charging through denial of service.
  • CISA lists the platform as deployed worldwide in the energy and transportation systems sectors, from a vendor headquartered in the Netherlands.
  • Monta supports OCPP 1.6 Security Profile 2, which is HTTP Basic Auth over TLS, and encourages charging operators to enable it.
  • Monta says it has added rate limiting and automated throttling that blocks rapid reconnection, ID brute-forcing and excessive command volume.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure On unauthenticated connections the station ID is the only credential, so anyone who knows or can predict a charger's ID can connect as that charger.
  • contradiction CISA's finding of no limit on authentication attempts conflicts with Monta's throttling statement, so operators cannot confirm from the advisory whether guessing of station credentials is blocked.
  • constraint Every version is affected, so operators have no upgrade to install, and the change open to them is moving each station onto authenticated connections.

Monta's WebSocket backend ties each session to a charging station's identifier, and it lets more than one endpoint connect under the same identifier [6]. Those endpoints require no authentication [3]. CISA says this design makes session identifiers predictable and lets an unauthorized party authenticate as another user [6]. According to the advisory, an attacker connected as a station can reach sensitive data, take unauthorized actions and escalate privileges, potentially compromising the entire system [3]. CISA classes the core flaw as CWE-306, Missing Authentication for Critical Function [11].

The same design also opens a path to denial of service. The advisory says an attacker can overwhelm the backend with valid session requests [6].

On attempt limits, CISA's finding is that the WebSocket API "lacks restrictions on the number of authentication requests," classed as CWE-307 [5]. Monta's description of its throttling appears in the mitigation section of the same advisory, presented as a vendor statement [9].

The missing limit matters most for stations that do authenticate. Security Profile 2 adds a credential to the connection [8], and CISA says the missing limit on attempts allows brute-force attacks to gain unauthorized access [5]. Monta also says that, per the OCPP specification, a new authenticated connection supersedes an existing session for the same station ID [10]. As Monta words it, the rule favours authenticated connections. A charger that still connects without credentials gets no protection from it against an impostor using its ID [1].

What to watch

  • Monta publishing a completion date for ending unauthenticated access, or CISA updating the advisory with a fixed version.
  • Any report of attackers using these flaws against charging operators on Monta's platform.
  • Independent testing of whether Monta's WebSocket throttling stops the brute-forcing described in CISA's finding that authentication attempts are not limited.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories