CVE-2021-34602
Summary
| CVE | CVE-2021-34602 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-27 16:15:00 UTC |
| Updated | 2022-05-11 17:46:00 UTC |
| Description | In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Bender | Cc612 | - | All | All | All |
| Operating System | Bender | Cc612 Firmware | All | All | All | All |
| Hardware | Bender | Cc613 | - | All | All | All |
| Operating System | Bender | Icc15xx Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VDE-2021-047 | CERT@VDE | CONFIRM | cert.vde.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Bender thanks Qianxin StarV Security Lab, China. The issue was coordinated by CERT@VDE.
There are currently no legacy QID mappings associated with this CVE.