Lucene search

K
cvelistCERTVDECVELIST:CVE-2021-34591
HistoryApr 27, 2022 - 3:15 p.m.

CVE-2021-34591 Bender Charge Controller: Local privilege Escalation

2022-04-2715:15:30
CWE-250
CERTVDE
www.cve.org
2
bender
charge controllers
local privilege escalation
authenticated attacker
root access
socat
ip udhcpc
ifplugd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.

CNA Affected

[
  {
    "product": "CC612",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "CC613",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ICC15xx",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ICC16xx",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.7

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVELIST:CVE-2021-34591