CVE-2021-34601
Summary
| CVE | CVE-2021-34601 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-27 16:15:00 UTC |
| Updated | 2022-05-11 17:46:00 UTC |
| Description | In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bender | Cc612 | - | All | All | All |
| Operating System | Bender | Cc612 Firmware | All | All | All | All |
| Hardware | Bender | Cc613 | - | All | All | All |
| Operating System | Bender | Icc15xx Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VDE-2021-047 | CERT@VDE | CONFIRM | cert.vde.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Bender thanks Qianxin StarV Security Lab, China. The issue was coordinated by CERT@VDE.
There are currently no legacy QID mappings associated with this CVE.