CVE Vulnerabilities

CVE-2021-34591

Execution with Unnecessary Privileges

Published: Apr 27, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacker could get root access via the suid applications socat, ip udhcpc and ifplugd.

Weakness

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

Affected Software

NameVendorStart VersionEnd Version
Cc612_firmwareBender5.11.0 (including)5.11.2 (excluding)
Cc612_firmwareBender5.12.0 (including)5.12.5 (excluding)
Cc612_firmwareBender5.13.0 (including)5.13.2 (excluding)
Cc612_firmwareBender5.20.0 (including)5.20.2 (excluding)

Potential Mitigations

References