CVE-2021-34591
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/04/2022
Last modified:
11/05/2022
Description
In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* | 5.11.0 (including) | 5.11.2 (excluding) |
| cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* | 5.12.0 (including) | 5.12.5 (excluding) |
| cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* | 5.13.0 (including) | 5.13.2 (excluding) |
| cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* | 5.20.0 (including) | 5.20.2 (excluding) |
| cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.11.0 (including) | 5.11.2 (excluding) |
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.12.0 (including) | 5.12.5 (excluding) |
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.13.0 (including) | 5.13.2 (excluding) |
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.20.0 (including) | 5.20.2 (excluding) |
| cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.11.0 (including) | 5.11.2 (excluding) |
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.12.0 (including) | 5.12.5 (excluding) |
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.13.0 (including) | 5.13.2 (excluding) |
| cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* | 5.20.0 (including) | 5.20.2 (excluding) |
| cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



