CVE-2021-34588
Bender Charge Controller: Unprotected data export
Severity Score
8.6
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .
En los Controladores de Carga Bender/ebee en múltiples versiones son propensos a una exportación de datos sin protección. La exportación de copias de seguridad está protegida por medio de una clave aleatoria. La clave es establecida en el inicio de sesión del usuario. Está vacía después de reiniciar
*Credits:
Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-06-10 CVE Reserved
- 2022-04-27 CVE Published
- 2024-09-16 CVE Updated
- 2025-01-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-425: Direct Request ('Forced Browsing')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2021-047 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|