CVE-2021-34589
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.
Affected (16)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.11.0 to 5.11.2 |
| Running on/with | Platform Versions |
|---|---|
Bender Cc612 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.11.0 to 5.11.2 | |
| From 5.12.0 to 5.12.5 |
| Running on/with | Platform Versions |
|---|---|
Bender Cc613 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.11.0 to 5.11.2 |
| Running on/with | Platform Versions |
|---|---|
Bender Icc15xx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 5.11.0 to 5.11.2 |
| Running on/with | Platform Versions |
|---|---|
Bender Icc16xx | All versions |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.