CVE-2021-34591

EUVD-2021-21241
In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CERTVDECNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 31%
Affected Products (NVD)
VendorProductVersion
bendercc612_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendercc612_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendercc612_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendercc612_firmware
5.20.0 ≤
𝑥
< 5.20.2
bendericc15xx_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendericc15xx_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendericc15xx_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendericc15xx_firmware
5.20.0 ≤
𝑥
< 5.20.2
bendericc15xx_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendericc15xx_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendericc15xx_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendericc15xx_firmware
5.20.0 ≤
𝑥
< 5.20.2
bendericc15xx_firmware
5.11.0 ≤
𝑥
< 5.11.2
bendericc15xx_firmware
5.12.0 ≤
𝑥
< 5.12.5
bendericc15xx_firmware
5.13.0 ≤
𝑥
< 5.13.2
bendericc15xx_firmware
5.20.0 ≤
𝑥
< 5.20.2
𝑥
= Vulnerable software versions