CVE-2021-34591

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2022
Last modified:
11/05/2022

Description

In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools