CVE-2021-34589
Bender Charge Controller: RFID leak
Severity Score
7.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.
En los controladores de carga Bender/ebee en múltiples versiones son propensos a un filtrado de RFID. El RFID del último evento de carga puede ser leído sin autenticación por medio de la interfaz web
*Credits:
Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE.
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-06-10 CVE Reserved
- 2022-04-27 CVE Published
- 2024-09-16 CVE Updated
- 2025-01-10 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2021-047 | 2022-10-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc612 Firmware Search vendor "Bender" for product "Cc612 Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Cc612 Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc612 Search vendor "Bender" for product "Cc612" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc613 Firmware Search vendor "Bender" for product "Cc613 Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc613 Firmware Search vendor "Bender" for product "Cc613 Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Cc613 Firmware Search vendor "Bender" for product "Cc613 Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Cc613 Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc613 Firmware Search vendor "Bender" for product "Icc613 Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Icc613 Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Cc613 Search vendor "Bender" for product "Cc613" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Icc15xx Search vendor "Bender" for product "Icc15xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Icc15xx Search vendor "Bender" for product "Icc15xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Icc15xx Search vendor "Bender" for product "Icc15xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc15xx Firmware Search vendor "Bender" for product "Icc15xx Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Icc15xx Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Icc15xx Search vendor "Bender" for product "Icc15xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc16xx Firmware Search vendor "Bender" for product "Icc16xx Firmware" | >= 5.11.0 < 5.11.2 Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.11.0 < 5.11.2" | - |
Affected
| in | Bender Search vendor "Bender" | Icc16xx Search vendor "Bender" for product "Icc16xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc16xx Firmware Search vendor "Bender" for product "Icc16xx Firmware" | >= 5.12.0 < 5.12.5 Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.12.0 < 5.12.5" | - |
Affected
| in | Bender Search vendor "Bender" | Icc16xx Search vendor "Bender" for product "Icc16xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc16xx Firmware Search vendor "Bender" for product "Icc16xx Firmware" | >= 5.13.0 < 5.13.2 Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.13.0 < 5.13.2" | - |
Affected
| in | Bender Search vendor "Bender" | Icc16xx Search vendor "Bender" for product "Icc16xx" | - | - |
Safe
|
Bender Search vendor "Bender" | Icc16xx Firmware Search vendor "Bender" for product "Icc16xx Firmware" | >= 5.20.0 < 5.20.2 Search vendor "Bender" for product "Icc16xx Firmware" and version " >= 5.20.0 < 5.20.2" | - |
Affected
| in | Bender Search vendor "Bender" | Icc16xx Search vendor "Bender" for product "Icc16xx" | - | - |
Safe
|