PatchSiren cyber security CVE debrief
CVE-2026-31903 IGL-Technologies CVE debrief
CVE-2026-31903 affects IGL-Technologies eParking.fi and is described by CISA as a lack of restrictions on the number of WebSocket authentication requests. In practical terms, that missing rate limiting can let a remote attacker flood authentication attempts, potentially disrupting charger telemetry or increasing the chance of brute-force access. CISA’s advisory also states that IGL-Technologies updated eParking’s OCPP servers with stronger authentication, device whitelisting, rate limiting, and enhanced monitoring.
- Vendor
- IGL-Technologies
- Product
- eParking.fi
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-19
- Original CVE updated
- 2026-03-19
- Advisory published
- 2026-03-19
- Advisory updated
- 2026-03-19
Who should care
Operators and administrators of IGL-Technologies eParking.fi, especially teams managing OCPP server deployments, charger telemetry, authentication controls, and monitoring for connected charging infrastructure.
Technical summary
The advisory describes a network-reachable WebSocket application interface that does not limit authentication requests. CISA says this can enable denial-of-service conditions by suppressing or mis-routing legitimate charger telemetry, and can also support brute-force attempts to gain unauthorized access. The supplied mitigation notes indicate that updated OCPP servers now enforce stronger security profiles, device-level whitelisting, rate limiting, and automated monitoring; CISA also notes that encrypted eParking OCPP deployments and IGL-Technologies’ eTolppa protocol are not impacted.
Defensive priority
High
Recommended defensive actions
- Apply the vendor-updated eParking OCPP server protections referenced in the advisory.
- Enforce strong authentication and modern security profiles for any exposed WebSocket authentication path.
- Add rate limiting or throttling for authentication requests to reduce brute-force and DoS risk.
- Restrict connections to known charging units using device-level whitelisting.
- Monitor for abnormal network and authentication activity and alert on spikes or repeated failures.
- Confirm whether your deployment uses the impacted eParking OCPP server path or one of the stated non-impacted encrypted/eTolppa deployments.
- Contact IGL-Technologies security at [email protected] if you need clarification on exposure or remediation.
Evidence notes
All substantive claims in this debrief are taken from the supplied CISA CSAF advisory for ICSA-26-078-07 / CVE-2026-31903 and its listed remediation notes. The source states that the WebSocket API lacks authentication request limits and that the resulting risks are denial of service via telemetry disruption and brute-force access attempts. Timing context uses the supplied advisory/CVE publication date of 2026-03-19; no earlier public issue date is asserted here.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31903 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31903
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31903 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31903
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-078-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-078-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.