CVE Vulnerabilities

CVE-2021-34591

Execution with Unnecessary Privileges

Published: Apr 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Affected Software

Name Vendor Start Version End Version
Cc612_firmware Bender 5.11.0 (including) 5.11.2 (excluding)
Cc612_firmware Bender 5.12.0 (including) 5.12.5 (excluding)
Cc612_firmware Bender 5.13.0 (including) 5.13.2 (excluding)
Cc612_firmware Bender 5.20.0 (including) 5.20.2 (excluding)

Potential Mitigations

References