CVE-2025-12357

8.3

ISO · 15118-2 Network and Application Protocol Requirements

A vulnerability in the SLAC protocol allows unauthenticated attackers to conduct man-in-the-middle attacks between electric vehicles and chargers using spoofed measurements.

Executive summary

A critical vulnerability in the ISO 15118-2 protocol allows unauthenticated attackers to perform man-in-the-middle attacks on electric vehicle charging communications.

Vulnerability

This flaw involves the manipulation of the Signal Level Attenuation Characterization (SLAC) protocol via spoofed measurements, which can be executed by an unauthenticated attacker in close proximity through electromagnetic induction.

Business impact

The ability for an attacker to intercept or manipulate traffic between an electric vehicle and a charging station poses a significant risk to the integrity of charging operations. Successful exploitation could lead to unauthorized service disruption or session manipulation, directly impacting the availability and reliability of charging infrastructure. With a CVSS score of 8.3, this vulnerability is classified as high severity, necessitating prompt attention to prevent operational downtime.

Remediation

Immediate Action: Consult the official CISA ICS advisory ICSA-25-303-01 and reach out to the specific charging equipment manufacturer to obtain and apply security patches or configuration updates.

Proactive Monitoring: Monitor network traffic logs associated with charging management systems for anomalous signal patterns or unexpected protocol negotiation sequences.

Compensating Controls: Implement physical security measures around charging stations to limit proximity and restrict unauthorized access to the immediate wireless environment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for man-in-the-middle attacks on critical charging infrastructure, stakeholders should prioritize identifying vulnerable hardware within their networks. Organizations must coordinate with their respective vendors to verify compliance with updated ISO 15118-2 security requirements and apply all available patches to mitigate the risk of protocol manipulation.

Sources

Originally found and disclosed by Mark I. Johnson of Southwest Research Institute reported this vulnerability to CISA., Sébastien Dudek of Penthertz disclosed this vulnerability publicly., Jean-Christophe Delaunay and Vincent Fargues of Synacktiv disclosed this vulnerability publicly., per the CVE Program record.