The Containment Era is here. →Explore

Executive Summary

In October 2025, a critical vulnerability (CVE-2025-12357) impacting the ISO 15118-2 standard for electric vehicle (EV) chargers was disclosed. The flaw centers on improper restriction of communication channels, specifically enabling attackers to exploit the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements. This manipulation facilitates man-in-the-middle attacks between EVs and compliant chargers, with attacks feasible wirelessly and in close proximity via electromagnetic induction. The vulnerability jeopardizes authentication and data exchange during the EV charging process but has not yet been publicly exploited.

The incident highlights escalating risks across connected infrastructure, especially as EV adoption surges globally. As regulators, manufacturers, and utility providers converge on charging protocols, the need for mandatory end-to-end encryption is increasingly urgent to safeguard against evolving threat actors targeting critical transportation sectors.

Why This Matters Now

The urgency stems from the rapid global expansion of EV infrastructure reliant on ISO 15118-2, which lacks mandatory encryption enforcement. This vulnerability demonstrates that attackers can bypass weak communication protections, making it critical for operators to adopt updated standards and security measures immediately.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The primary gap was lack of enforced end-to-end encrypted communication and authentication, making systems susceptible to man-in-the-middle attacks and non-compliance with frameworks like NIST SP 800-53 and PCI DSS.

Cloud Native Security Fabric Mitigations and ControlsCNSF

CNSF controls such as encrypted traffic enforcement, zero trust segmentation, robust egress policies, and distributed visibility would have prevented or significantly constrained this multi-stage man-in-the-middle attack by isolating east-west paths, detecting anomalous traffic, and ensuring that only intended endpoints communicate over protected channels.

Initial Compromise

Control: Encrypted Traffic (HPE)

Mitigation: Prevents unauthorized interception and manipulation of communications.

Privilege Escalation

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Detects anomalies or signature-based compromise attempts on in-transit traffic.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Restricts lateral movement across workloads and services.

Command & Control

Control: Egress Security & Policy Enforcement

Mitigation: Detects and blocks unsanctioned outbound connections.

Exfiltration

Control: Multicloud Visibility & Control

Mitigation: Provides centralized observability and enables real-time detection of data exfiltration events.

Impact (Mitigations)

Limits blast radius and prevents unauthorized impact propagation.

Impact at a Glance

Affected Business Functions

  • EV Charging Operations
  • Vehicle-to-Grid Communications
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of vehicle and charging station communication data, leading to unauthorized access or manipulation of charging sessions.

Recommended Actions

  • Enforce end-to-end encryption (e.g., TLS, MACsec) for all EV and charger communications as required by latest standards.
  • Deploy zero trust segmentation and east-west traffic controls to restrict lateral movement and internal attack propagation.
  • Implement egress filtering and continuous monitoring to block unauthorized external connections from critical infrastructure.
  • Gain centralized multicloud visibility to promptly detect and respond to anomalous or suspicious traffic and access patterns.
  • Leverage real-time inline threat detection and policy enforcement to quickly contain man-in-the-middle or protocol exploitation attempts.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image