Back to all lessons
Awareness Lessons
3 months ago

Critical Access Control Flaws Expose EV Charging Infrastructure

Multiple critical vulnerabilities in Hydro-Québec's Le Circuit Electrique EV charging backend expose a systemic failure in secure-by-design principles for industrial IoT infrastructure. Improper access control, weak brute-force protections, and insufficient session expiration collectively create pathways for privilege escalation and denial-of-service attacks. This matters because electric vehicle charging networks are increasingly classified as critical infrastructure, meaning disruptions can have cascading societal and economic impacts. The reactive mitigation — disabling OCPP on most stations — highlights a lack of proactive vulnerability management and secure development lifecycle practices. Security controls must be embedded during development, not bolted on after public disclosure.

Tactical Insight

Immediate actions

  • Audit all EV charging backend systems for improper access control, missing rate limiting, and session management weaknesses.
  • Enforce multi-factor authentication and strict session expiration policies on all administrative and operator-facing interfaces.
  • Disable or isolate any OCPP endpoints that cannot be immediately hardened until a proper fix is deployed.

Long-term improvements

  • Integrate secure development lifecycle (SDL) practices, including threat modeling, for all OT/IoT backend systems before deployment.
  • Establish a formal vulnerability disclosure and patch management program specifically covering operational technology and charging infrastructure.
  • Apply network segmentation to isolate EV charging backend systems from corporate networks and the public internet.

Detection measures

  • Deploy anomaly detection and rate-limiting monitoring on authentication endpoints to identify brute-force or credential-stuffing attempts in real time.
  • Implement centralized logging for all OCPP communications and backend API calls to enable forensic investigation after suspicious activity.
  • Schedule regular third-party penetration testing of EV charging infrastructure at least annually.