CVE-2021-34589

In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface.
References
Link Resource
https://cert.vde.com/en/advisories/VDE-2021-047 Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:bender:cc613_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc613_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:cc613_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc613_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:icc15xx:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:bender:icc16xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc16xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc16xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:bender:icc16xx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bender:icc16xx:-:*:*:*:*:*:*:*

Information

Published : 2022-04-27 09:15

Updated : 2022-10-28 10:34


NVD link : CVE-2021-34589

Mitre link : CVE-2021-34589


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

bender

  • icc16xx
  • icc613_firmware
  • cc612
  • icc15xx_firmware
  • cc613_firmware
  • cc612_firmware
  • cc613
  • icc15xx
  • icc16xx_firmware