CVE-2021-34588
Estado: ModificadaAlta (8.6)—
In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot .
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Puntuación base: 8.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.90%
- Percentil entre todas las CVEs puntuadas: 58
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-425
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-34588",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "info@cert.vde.com",
"affectedData": [
{
"vendor": "Bender / ebee",
"product": "CC612",
"versions": [
{
"status": "affected",
"version": "5.11.x",
"lessThan": "5.11.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.12.x",
"lessThan": "5.12.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.13.x",
"lessThan": "5.13.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.20.x",
"lessThan": "5.20.2",
"versionType": "custom"
}
]
},
{
"vendor": "Bender / ebee",
"product": "CC613",
"versions": [
{
"status": "affected",
"version": "5.11.x",
"lessThan": "5.11.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.12.x",
"lessThan": "5.12.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.13.x",
"lessThan": "5.13.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.20.x",
"lessThan": "5.20.2",
"versionType": "custom"
}
]
},
{
"vendor": "Bender / ebee",
"product": "ICC15xx",
"versions": [
{
"status": "affected",
"version": "5.11.x",
"lessThan": "5.11.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.12.x",
"lessThan": "5.12.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.13.x",
"lessThan": "5.13.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.20.x",
"lessThan": "5.20.2",
"versionType": "custom"
}
]
},
{
"vendor": "Bender / ebee",
"product": "ICC16xx",
"versions": [
{
"status": "affected",
"version": "5.11.x",
"lessThan": "5.11.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.12.x",
"lessThan": "5.12.5",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.13.x",
"lessThan": "5.13.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "5.20.x",
"lessThan": "5.20.2",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-04-27T16:15:10.870",
"references": [
{
"url": "https://cert.vde.com/en/advisories/VDE-2021-047",
"tags": [
"Third Party Advisory"
],
"source": "info@cert.vde.com"
},
{
"url": "https://cert.vde.com/en/advisories/VDE-2021-047",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "info@cert.vde.com",
"description": [
{
"lang": "en",
"value": "CWE-425"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In Bender/ebee Charge Controllers in multiple versions are prone to unprotected data export. Backup export is protected via a random key. The key is set at user login. It is empty after reboot ."
},
{
"lang": "es",
"value": "En los Controladores de Carga Bender/ebee en múltiples versiones son propensos a una exportación de datos sin protección. La exportación de copias de seguridad está protegida por medio de una clave aleatoria. La clave es establecida en el inicio de sesión del usuario. Está vacía después de reiniciar"
}
],
"lastModified": "2026-06-17T03:56:11.270",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81AED2C8-71EE-4BFC-949C-D63F998CD1ED",
"versionEndExcluding": "5.11.2",
"versionStartIncluding": "5.11.0"
},
{
"criteria": "cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "609125CC-4748-4507-8CF2-1752FF89B203",
"versionEndExcluding": "5.12.5",
"versionStartIncluding": "5.12.0"
},
{
"criteria": "cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C6FEC2C0-7F12-434A-9070-9A0F19379D25",
"versionEndExcluding": "5.13.2",
"versionStartIncluding": "5.13.0"
},
{
"criteria": "cpe:2.3:o:bender:cc612_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E80EBD0C-D852-4EF7-B0EA-89124683939C",
"versionEndExcluding": "5.20.2",
"versionStartIncluding": "5.20.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:bender:cc612:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9B48F3A5-C59D-40B6-ADBB-76FA536C78FE"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B078039-C644-42DE-8122-300415D69854",
"versionEndExcluding": "5.11.2",
"versionStartIncluding": "5.11.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D687057F-58C9-4463-BEF2-BE4CA428F9AD",
"versionEndExcluding": "5.12.5",
"versionStartIncluding": "5.12.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88D208BE-6401-489E-BBE7-1ABBEB14CF52",
"versionEndExcluding": "5.13.2",
"versionStartIncluding": "5.13.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B36AF92-1F52-45AA-BAAF-0D94EB0B2FF2",
"versionEndExcluding": "5.20.2",
"versionStartIncluding": "5.20.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2FEFDDEB-23FB-474C-9A91-EDA35837D34B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B078039-C644-42DE-8122-300415D69854",
"versionEndExcluding": "5.11.2",
"versionStartIncluding": "5.11.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D687057F-58C9-4463-BEF2-BE4CA428F9AD",
"versionEndExcluding": "5.12.5",
"versionStartIncluding": "5.12.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88D208BE-6401-489E-BBE7-1ABBEB14CF52",
"versionEndExcluding": "5.13.2",
"versionStartIncluding": "5.13.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B36AF92-1F52-45AA-BAAF-0D94EB0B2FF2",
"versionEndExcluding": "5.20.2",
"versionStartIncluding": "5.20.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2FEFDDEB-23FB-474C-9A91-EDA35837D34B"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B078039-C644-42DE-8122-300415D69854",
"versionEndExcluding": "5.11.2",
"versionStartIncluding": "5.11.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D687057F-58C9-4463-BEF2-BE4CA428F9AD",
"versionEndExcluding": "5.12.5",
"versionStartIncluding": "5.12.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88D208BE-6401-489E-BBE7-1ABBEB14CF52",
"versionEndExcluding": "5.13.2",
"versionStartIncluding": "5.13.0"
},
{
"criteria": "cpe:2.3:o:bender:icc15xx_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0B36AF92-1F52-45AA-BAAF-0D94EB0B2FF2",
"versionEndExcluding": "5.20.2",
"versionStartIncluding": "5.20.0"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:bender:cc613:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2FEFDDEB-23FB-474C-9A91-EDA35837D34B"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "info@cert.vde.com"
}