// For flags

CVE-2021-34587

Bender Charge Controller: Long URL could lead to webserver crash

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

En los Controladores de Carga Bender/ebee en mĂșltiples versiones, una URL larga podrĂ­a conllevar a un bloqueo del servidor web. La URL es usada como entrada de un sprintf a una variable de pila

*Credits: Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE.
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-06-10 CVE Reserved
  • 2022-04-27 CVE Published
  • 2024-09-17 CVE Updated
  • 2025-01-10 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-121: Stack-based Buffer Overflow
  • CWE-787: Out-of-bounds Write
CAPEC
References (1)
URL Tag Source
https://cert.vde.com/en/advisories/VDE-2021-047 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Bender
Search vendor "Bender"
Cc612 Firmware
Search vendor "Bender" for product "Cc612 Firmware"
>= 5.11.0 < 5.11.2
Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.11.0 < 5.11.2"
-
Affected
in Bender
Search vendor "Bender"
Cc612
Search vendor "Bender" for product "Cc612"
--
Safe
Bender
Search vendor "Bender"
Cc612 Firmware
Search vendor "Bender" for product "Cc612 Firmware"
>= 5.12.0 < 5.12.5
Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.12.0 < 5.12.5"
-
Affected
in Bender
Search vendor "Bender"
Cc612
Search vendor "Bender" for product "Cc612"
--
Safe
Bender
Search vendor "Bender"
Cc612 Firmware
Search vendor "Bender" for product "Cc612 Firmware"
>= 5.13.0 < 5.13.2
Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.13.0 < 5.13.2"
-
Affected
in Bender
Search vendor "Bender"
Cc612
Search vendor "Bender" for product "Cc612"
--
Safe
Bender
Search vendor "Bender"
Cc612 Firmware
Search vendor "Bender" for product "Cc612 Firmware"
>= 5.20.0 < 5.20.2
Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.20.0 < 5.20.2"
-
Affected
in Bender
Search vendor "Bender"
Cc612
Search vendor "Bender" for product "Cc612"
--
Safe
Bender
Search vendor "Bender"
Cc613 Firmware
Search vendor "Bender" for product "Cc613 Firmware"
>= 5.11.0 < 5.11.2
Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.11.0 < 5.11.2"
-
Affected
in Bender
Search vendor "Bender"
Cc613
Search vendor "Bender" for product "Cc613"
--
Safe
Bender
Search vendor "Bender"
Cc613 Firmware
Search vendor "Bender" for product "Cc613 Firmware"
>= 5.12.0 < 5.12.5
Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.12.0 < 5.12.5"
-
Affected
in Bender
Search vendor "Bender"
Cc613
Search vendor "Bender" for product "Cc613"
--
Safe
Bender
Search vendor "Bender"
Cc613 Firmware
Search vendor "Bender" for product "Cc613 Firmware"
>= 5.13.0 < 5.13.2
Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.13.0 < 5.13.2"
-
Affected
in Bender
Search vendor "Bender"
Cc613
Search vendor "Bender" for product "Cc613"
--
Safe
Bender
Search vendor "Bender"
Cc613 Firmware
Search vendor "Bender" for product "Cc613 Firmware"
>= 5.20.0 < 5.20.2
Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.20.0 < 5.20.2"
-
Affected
in Bender
Search vendor "Bender"
Cc613
Search vendor "Bender" for product "Cc613"
--
Safe
Bender
Search vendor "Bender"
Icc15xx Firmware
Search vendor "Bender" for product "Icc15xx Firmware"
>= 5.11.0 < 5.11.2
Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.11.0 < 5.11.2"
-
Affected
in Bender
Search vendor "Bender"
Icc15xx
Search vendor "Bender" for product "Icc15xx"
--
Safe
Bender
Search vendor "Bender"
Icc15xx Firmware
Search vendor "Bender" for product "Icc15xx Firmware"
>= 5.12.0 < 5.12.5
Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.12.0 < 5.12.5"
-
Affected
in Bender
Search vendor "Bender"
Icc15xx
Search vendor "Bender" for product "Icc15xx"
--
Safe
Bender
Search vendor "Bender"
Icc15xx Firmware
Search vendor "Bender" for product "Icc15xx Firmware"
>= 5.13.0 < 5.13.2
Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.13.0 < 5.13.2"
-
Affected
in Bender
Search vendor "Bender"
Icc15xx
Search vendor "Bender" for product "Icc15xx"
--
Safe
Bender
Search vendor "Bender"
Icc15xx Firmware
Search vendor "Bender" for product "Icc15xx Firmware"
>= 5.20.0 < 5.20.2
Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.20.0 < 5.20.2"
-
Affected
in Bender
Search vendor "Bender"
Icc15xx
Search vendor "Bender" for product "Icc15xx"
--
Safe
Bender
Search vendor "Bender"
Icc16xx Firmware
Search vendor "Bender" for product "Icc16xx Firmware"
>= 5.11.0 < 5.11.2
Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.11.0 < 5.11.2"
-
Affected
in Bender
Search vendor "Bender"
Icc16xx
Search vendor "Bender" for product "Icc16xx"
--
Safe
Bender
Search vendor "Bender"
Icc16xx Firmware
Search vendor "Bender" for product "Icc16xx Firmware"
>= 5.12.0 < 5.12.5
Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.12.0 < 5.12.5"
-
Affected
in Bender
Search vendor "Bender"
Icc16xx
Search vendor "Bender" for product "Icc16xx"
--
Safe
Bender
Search vendor "Bender"
Icc16xx Firmware
Search vendor "Bender" for product "Icc16xx Firmware"
>= 5.13.0 < 5.13.2
Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.13.0 < 5.13.2"
-
Affected
in Bender
Search vendor "Bender"
Icc16xx
Search vendor "Bender" for product "Icc16xx"
--
Safe
Bender
Search vendor "Bender"
Icc16xx Firmware
Search vendor "Bender" for product "Icc16xx Firmware"
>= 5.20.0 < 5.20.2
Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.20.0 < 5.20.2"
-
Affected
in Bender
Search vendor "Bender"
Icc16xx
Search vendor "Bender" for product "Icc16xx"
--
Safe
Ibm
Search vendor "Ibm"
Ibm Rational Lifecycle Integration Adapter For Windchill
Search vendor "Ibm" for product " Ibm Rational Lifecycle Integration Adapter For Windchill"
1.0.0
Search vendor "Ibm" for product " Ibm Rational Lifecycle Integration Adapter For Windchill" and version "1.0.0"
-
Affected