In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.
References
Link | Resource |
---|---|
https://cert.vde.com/en/advisories/VDE-2021-047 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Information
Published : 2022-04-27 09:15
Updated : 2022-05-11 10:46
NVD link : CVE-2021-34601
Mitre link : CVE-2021-34601
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
bender
- icc15xx_firmware
- cc613
- cc612_firmware
- cc612