PatchSiren

ISO 15118-2 Network and Application Protocol Requirements CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ISO 15118-2 Network and Application Protocol Requirements CVE published 2025-10-30

CVE-2025-12357

CVE-2025-12357 describes a protocol-level vulnerability in ISO 15118-2, the international standard governing communication between electric vehicles (EVs) and charging infrastructure. The Signal Level Attenuation Characterization (SLAC) protocol, used to establish the initial link between vehicle and charger, can be manipulated through spoofed measurements to enable man-in-the-middle positioning. The atta [truncated]