CVE-2021-34588
27.04.2022, 16:15
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .
Vendor | Product | Version |
---|---|---|
bender | cc612_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | cc612_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | cc612_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | cc612_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
bender | icc15xx_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | icc15xx_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | icc15xx_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | icc15xx_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
bender | icc15xx_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | icc15xx_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | icc15xx_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | icc15xx_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
bender | icc15xx_firmware | 5.11.0 ≤ 𝑥 < 5.11.2 |
bender | icc15xx_firmware | 5.12.0 ≤ 𝑥 < 5.12.5 |
bender | icc15xx_firmware | 5.13.0 ≤ 𝑥 < 5.13.2 |
bender | icc15xx_firmware | 5.20.0 ≤ 𝑥 < 5.20.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration