CVE-2021-34587
27.04.2022, 16:15
In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | _ibm_rational_lifecycle_integration_adapter_for_windchill | 1.0.0 |
bender | cc612_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | cc612_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | cc612_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | cc612_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
bender | cc613_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | cc613_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | cc613_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | cc613_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
bender | icc15xx_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | icc15xx_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | icc15xx_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | icc15xx_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
bender | icc16xx_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | icc16xx_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | icc16xx_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | icc16xx_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-121 - Stack-based Buffer OverflowA stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
- CWE-787 - Out-of-bounds WriteThe software writes data past the end, or before the beginning, of the intended buffer.