CVE-2021-34591

In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
bendercc612_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendercc612_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendercc612_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendercc612_firmware
5.20.0 ≤
𝑥
< 5.20.2
bendericc15xx_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendericc15xx_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendericc15xx_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendericc15xx_firmware
5.20.0 ≤
𝑥
< 5.20.2
bendericc15xx_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendericc15xx_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendericc15xx_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendericc15xx_firmware
5.20.0 ≤
𝑥
< 5.20.2
bendericc15xx_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendericc15xx_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendericc15xx_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendericc15xx_firmware
5.20.0 ≤
𝑥
< 5.20.2
𝑥
= Vulnerable software versions