Lucene search

K
cvelistCERTVDECVELIST:CVE-2021-34592
HistoryApr 27, 2022 - 3:15 p.m.

CVE-2021-34592 Bender Charge Controller: Command injection via Web interface

2022-04-2715:15:31
CWE-77
CERTVDE
www.cve.org
4
cve-2021-34592
command injection
web interface
bender charge controller

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

31.7%

In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.

CNA Affected

[
  {
    "product": "CC612",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "CC613",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ICC15xx",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  },
  {
    "product": "ICC16xx",
    "vendor": "Bender / ebee",
    "versions": [
      {
        "lessThan": "5.11.2",
        "status": "affected",
        "version": "5.11.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.12.5",
        "status": "affected",
        "version": "5.12.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.13.2",
        "status": "affected",
        "version": "5.13.x",
        "versionType": "custom"
      },
      {
        "lessThan": "5.20.2",
        "status": "affected",
        "version": "5.20.x",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9.1

Confidence

High

EPSS

0.001

Percentile

31.7%

Related for CVELIST:CVE-2021-34592