CVE-2021-34588

Severity CVSS v4.0:
Pending analysis
Type:
CWE-425 Direct Request ('Forced Browsing')
Publication date:
27/04/2022
Last modified:
11/05/2022

Description

In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.11.0 (including) 5.11.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.12.0 (including) 5.12.5 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.13.0 (including) 5.13.2 (excluding)
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:* 5.20.0 (including) 5.20.2 (excluding)
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools