CVE-2021-34591

In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2021-047 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*

History

11 May 2022, 17:51

Type Values Removed Values Added
References (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-047 - (CONFIRM) https://cert.vde.com/en/advisories/VDE-2021-047 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
First Time Bender cc612
Bender cc612 Firmware
Bender cc613
Bender icc15xx Firmware
Bender
CPE cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*

27 Apr 2022, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-27 16:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-34591

Mitre link : CVE-2021-34591

CVE.ORG link : CVE-2021-34591


JSON object : View

Products Affected

bender

  • cc612_firmware
  • cc612
  • icc15xx_firmware
  • cc613
CWE
CWE-250

Execution with Unnecessary Privileges