" " indicates required fields
By David Mor Ofek, Head of Product
On July 2023 researchers at Saiflow published a report highlighting three critical vulnerabilities found in ABB’s ChargerSync platform which serves as a Charging Station Management System (CSMS) provider owned by ABB. With more than one million EV chargers and 50,000 DC fast chargers across 85 markets, ABB is a global leader in EV charging solutions. The vulnerabilities allowed unauthorized access to files uploaded by other users, bypassing the required provisioning PIN code for authentication and hijacking a charger open charge point protocol (OCPP) connection.
In this blog post, I will address the vulnerabilities discovered in ABB’s ChargerSync platform and suggest recommendations on how EV charging infrastructure companies, from vendors to operators, can mitigate these risks in the future.
The vulnerabilities discovered in the ChargerSync platform were centered around a specific application programming interface (API) with several security flaws. These vulnerabilities can be explained in a way that is easy to understand.
First, we want to applaud ABB for recognizing, taking responsibility, and dealing with the reported vulnerabilities quickly and efficiently. As reported, ABB adopted several mitigation principles to close the vulnerabilities in the ChargerSync API.
The main purpose of this blog is to try and provide recommended processes and measures to help reduce the risk of exposures and vulnerabilities by using principles of security, operations, and validation by design.
The following principles can guide security teams in making sure the product (in this case) of the CSMS is secure from concept/design to production and back.
As an example, in the TARA process, an assessor with proper tooling and detailed attack trees designed for EV charging infrastructure might have decided to deal with the OCPP-related threat of OCPP hijacking by implementing OCPP Security Profile 2 as part of the necessary security controls in the design.
In all of the vulnerabilities discovered in the ChargerSync CSMS, managing the risk and validating the security controls prior to release or post-deployment could have prevented the vulnerabilities. For example, validating whether the API is protected with a pin code or whether the file upload mechanism is using a sequential identifier would have verified the security controls are in place and mitigating the risk to the model.
C2A Security’s EVSec Platform is specifically designed to assist product-centric companies with addressing the above challenges. The product security challenge exists in the automotive industry as in other complex and safety-critical products such as EV charging management and infrastructure. Security controls need to be chosen correctly with proper threat analysis and risk assessment, and later the risk needs to be managed throughout the product lifecycle by performing validation within the CI/CD pipeline and vulnerability management post-deployment.
By integrating a virtual cyber model and strategically layering security information at different stages of the product security lifecycle, EVSec provides a comprehensive and holistic view of the product’s security status. Through the implementation of automation, EVSec further streamlines the process, resulting in reduced time and costs associated with product security efforts.
C2A Security deeply understands the ever-evolving software landscape and the critical importance of continuous product security lifecycle management. EVSec’s unique “breathing” approach to threat modeling ensures that risk management is dynamic, up-to-date, and relevant throughout the entire product lifecycle, facilitating operations and overall security by design.
If you’re looking to improve your security posture, better adhere to regulations to minimize your product security efforts using advanced automation, schedule a demo today and discover how our EVSec Platform can empower your product security development and operations. Own your risk, and reduce your costs and time to deployment today.
If you’re looking to improve your security posture and better adhere to regulations to minimize your liability, schedule a demo today and discover how our EVSec Platform can empower your security operations. Own your risk management, today.
Dynamic threat modeling and risk assessment aligned with global regulations
LLM-agnostic generative AI layer powering automation across every module
Aggregated threat feed contextualized against your actual products
Generate, manage, and triage all BOMs and vulnerabilities across the lifecycle
Quantitative optimization of mitigation strategy and security control allocation
Configurable dashboards and reports across every EVSec data layer
Extract software composition and risk from firmware and binaries without source code
Optimized anomaly detection for Ethernet and CAN, plus ECU runtime protection
Quantify and manage cybersecurity risk for products operating in the field
Enrich SOC events with deep product and architecture context
Context-driven test and validation with intelligent fuzzing, integrated into CI/CD
AI-powered static analysis integrated into CI/CD with reduced false positives
Foundational layer: cyber model, workspaces, and integration backbone to DevOps toolchain
Out-of-the-box and customizable workflows for regulatory and security processes
Centralized compliance management with evidence generated from live data