{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/everest/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:everest:everest-core:*:*:*:*:*:*:*:*","cpe:2.3:o:linuxfoundation:everest:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2025-68137"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["everest-core (\u003c 2025.10.0)"],"_cs_severities":["high"],"_cs_tags":["dos","vulnerability","cve-2025-68137"],"_cs_type":"advisory","_cs_vendors":["EVerest"],"content_html":"\u003cp\u003eEVerest everest-core versions prior to 2025.10.0 contain an integer overflow vulnerability in the SdpPacket::parse_header() function. The vulnerability occurs because the header length field (4 bytes) is added to the fixed header size (8 bytes) without performing an overflow check. When a length field is provided that causes this addition to exceed the capacity of an unsigned integer (near UINT_MAX), it triggers an incorrect size calculation.\u003c/p\u003e\n\u003cp\u003eThis flaw can be exploited by an unauthenticated attacker sending a malformed SDP packet over the network. If the service is running over TCP, the overflow causes an infinite loop in the packet parsing logic, leading to a Denial of Service. If the service is running over TLS, the resulting incorrect size calculation can trigger a stack-based buffer overflow, which may allow for remote code execution. This vulnerability is documented as CVE-2025-68137 and a functional proof-of-concept exploit exists for the DoS condition.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in service disruption, as the affected instance of EVerest will hang indefinitely upon processing a malicious SDP packet. In TLS-enabled deployments, the stack-based buffer overflow presents a significant risk of remote code execution, allowing an attacker to gain control over the affected system. This vulnerability affects systems using EVerest core versions prior to 2025.10.0, impacting environments where the software is deployed for EV charging infrastructure management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of EVerest everest-core to version 2025.10.0 or later immediately to patch CVE-2025-68137.\u003c/li\u003e\n\u003cli\u003eRestrict network access to EVerest management interfaces to trusted IP addresses to prevent unauthenticated access to the SDP service.\u003c/li\u003e\n\u003cli\u003eDeploy network-level inspection to identify and block SDP packets with highly anomalous length fields (near 0xFFFFFFFF).\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-02T15:43:34Z","date_published":"2026-09-02T15:43:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-everest-dos/","summary":"An integer overflow vulnerability (CVE-2025-68137) in EVerest everest-core versions prior to 2025.10.0 allows unauthenticated attackers to cause a Denial of Service or potential code execution.","title":"Integer Overflow Vulnerability in EVerest SDP Parsing","url":"https://feed.craftedsignal.io/briefs/2026-09-everest-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - EVerest","version":"https://jsonfeed.org/version/1.1"}