All the vulnerabilites related to Bender - ICC16xx
cve-2025-41708
Vulnerability from cvelistv5
Published
2025-09-08 06:38
Modified
2025-09-08 18:04
Severity ?
EPSS score ?
Summary
Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface
References
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41708", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-09-08T18:03:02.845880Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-08T18:04:06.675Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "CC612", "vendor": "Bender", "versions": [ { "lessThanOrEqual": "all versions", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "CC613", "vendor": "Bender", "versions": [ { "lessThanOrEqual": "all versions", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "ICC15xx", "vendor": "Bender", "versions": [ { "lessThanOrEqual": "all versions", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "ICC16xx", "vendor": "Bender", "versions": [ { "lessThanOrEqual": "all versions", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "ICC13xx", "vendor": "Bender", "versions": [ { "lessThanOrEqual": "all versions", "status": "affected", "version": "0.0.0", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Dr. Matthias Kesenheimer by SySS GmbH" }, { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Sebastian Hamann by SySS GmbH" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission.\u003cbr\u003e" } ], "value": "Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface. An unauthenticated attacker on the same network could exploit this to learn sensitive data during transmission." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "HIGH", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.4, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-319", "description": "CWE-319 Cleartext Transmission of Sensitive Information", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-08T06:38:50.386Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://certvde.com/de/advisories/VDE-2025-084" } ], "source": { "advisory": "VDE-2025-084", "defect": [ "CERT@VDE#641854" ], "discovery": "UNKNOWN" }, "title": "Cleartext Transmission of Sensitive Data via Insecure HTTP Web Interface", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2025-41708", "datePublished": "2025-09-08T06:38:50.386Z", "dateReserved": "2025-04-16T11:17:48.311Z", "dateUpdated": "2025-09-08T18:04:06.675Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2021-34587
Vulnerability from cvelistv5
Published
2022-04-27 15:15
Modified
2024-09-17 02:58
Severity ?
EPSS score ?
Summary
Bender Charge Controller: Long URL could lead to webserver crash
References
▼ | URL | Tags |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2021-047 | x_refsource_CONFIRM |
Impacted products
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T00:19:46.977Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://cert.vde.com/en/advisories/VDE-2021-047" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "CC612", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] }, { "product": "CC613", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] }, { "product": "ICC15xx", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] }, { "product": "ICC16xx", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "value": "Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE." } ], "datePublic": "2022-04-27T00:00:00", "descriptions": [ { "lang": "en", "value": "In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-121", "description": "CWE-121 Stack-based Buffer Overflow", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-27T15:15:23", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://cert.vde.com/en/advisories/VDE-2021-047" } ], "source": { "advisory": "VDE-2021-047", "defect": [ "CERT@VDE#64088" ], "discovery": "EXTERNAL" }, "title": "Bender Charge Controller: Long URL could lead to webserver crash", "x_generator": { "engine": "Vulnogram 0.0.9" }, "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "info@cert.vde.com", "DATE_PUBLIC": "2022-04-27T10:00:00.000Z", "ID": "CVE-2021-34587", "STATE": "PUBLIC", "TITLE": "Bender Charge Controller: Long URL could lead to webserver crash" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "CC612", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } }, { "product_name": "CC613", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } }, { "product_name": "ICC15xx", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } }, { "product_name": "ICC16xx", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } } ] }, "vendor_name": "Bender / ebee" } ] } }, "credit": [ { "lang": "eng", "value": "Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE." } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable." } ] }, "generator": { "engine": "Vulnogram 0.0.9" }, "impact": { "cvss": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-121 Stack-based Buffer Overflow" } ] } ] }, "references": { "reference_data": [ { "name": "https://cert.vde.com/en/advisories/VDE-2021-047", "refsource": "CONFIRM", "url": "https://cert.vde.com/en/advisories/VDE-2021-047" } ] }, "source": { "advisory": "VDE-2021-047", "defect": [ "CERT@VDE#64088" ], "discovery": "EXTERNAL" } } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2021-34587", "datePublished": "2022-04-27T15:15:24.084444Z", "dateReserved": "2021-06-10T00:00:00", "dateUpdated": "2024-09-17T02:58:12.456Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2025-41682
Vulnerability from cvelistv5
Published
2025-09-08 06:38
Modified
2025-09-08 18:04
Severity ?
EPSS score ?
Summary
Credential Disclosure via Insecure Storage on Charge Controller
References
{ "containers": { "adp": [ { "metrics": [ { "other": { "content": { "id": "CVE-2025-41682", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "timestamp": "2025-09-08T18:04:27.258671Z", "version": "2.0.3" }, "type": "ssvc" } } ], "providerMetadata": { "dateUpdated": "2025-09-08T18:04:43.038Z", "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP" }, "title": "CISA ADP Vulnrichment" } ], "cna": { "affected": [ { "defaultStatus": "unaffected", "product": "CC612", "vendor": "Bender", "versions": [ { "lessThan": "5.33.3", "status": "affected", "version": "5.30.2", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "CC613", "vendor": "Bender", "versions": [ { "lessThan": "5.33.3", "status": "affected", "version": "5.30.2", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "ICC16xx", "vendor": "Bender", "versions": [ { "lessThan": "5.33.3", "status": "affected", "version": "5.30.2", "versionType": "semver" } ] }, { "defaultStatus": "unaffected", "product": "ICC13xx", "vendor": "Bender", "versions": [ { "lessThan": "5.33.3", "status": "affected", "version": "5.30.2", "versionType": "semver" } ] } ], "credits": [ { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Dr. Matthias Kesenheimer by SySS GmbH" }, { "lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Sebastian Hamann by SySS GmbH" } ], "descriptions": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password.\u003cbr\u003e" } ], "value": "An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.8, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ] } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-522", "description": "CWE-522 Insufficiently Protected Credentials", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2025-09-08T06:38:31.579Z", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "url": "https://certvde.com/de/advisories/VDE-2025-061" } ], "source": { "advisory": "VDE-2025-061", "defect": [ "CERT@VDE#641819" ], "discovery": "UNKNOWN" }, "title": "Credential Disclosure via Insecure Storage on Charge Controller", "x_generator": { "engine": "Vulnogram 0.1.0-dev" } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2025-41682", "datePublished": "2025-09-08T06:38:31.579Z", "dateReserved": "2025-04-16T11:17:48.309Z", "dateUpdated": "2025-09-08T18:04:43.038Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }
cve-2021-34589
Vulnerability from cvelistv5
Published
2022-04-27 15:15
Modified
2024-09-16 21:08
Severity ?
EPSS score ?
Summary
Bender Charge Controller: RFID leak
References
▼ | URL | Tags |
---|---|---|
https://cert.vde.com/en/advisories/VDE-2021-047 | x_refsource_CONFIRM |
Impacted products
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T00:19:46.936Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_CONFIRM", "x_transferred" ], "url": "https://cert.vde.com/en/advisories/VDE-2021-047" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "CC612", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] }, { "product": "CC613", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] }, { "product": "ICC15xx", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] }, { "product": "ICC16xx", "vendor": "Bender / ebee", "versions": [ { "lessThan": "5.11.2", "status": "affected", "version": "5.11.x", "versionType": "custom" }, { "lessThan": "5.12.5", "status": "affected", "version": "5.12.x", "versionType": "custom" }, { "lessThan": "5.13.2", "status": "affected", "version": "5.13.x", "versionType": "custom" }, { "lessThan": "5.20.2", "status": "affected", "version": "5.20.x", "versionType": "custom" } ] } ], "credits": [ { "lang": "en", "value": "Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE." } ], "datePublic": "2022-04-27T00:00:00", "descriptions": [ { "lang": "en", "value": "In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface." } ], "metrics": [ { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" } } ], "problemTypes": [ { "descriptions": [ { "cweId": "CWE-200", "description": "CWE-200 Information Exposure", "lang": "en", "type": "CWE" } ] } ], "providerMetadata": { "dateUpdated": "2022-04-27T15:15:27", "orgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "shortName": "CERTVDE" }, "references": [ { "tags": [ "x_refsource_CONFIRM" ], "url": "https://cert.vde.com/en/advisories/VDE-2021-047" } ], "source": { "advisory": "VDE-2021-047", "defect": [ "CERT@VDE#64088" ], "discovery": "EXTERNAL" }, "title": "Bender Charge Controller: RFID leak", "x_generator": { "engine": "Vulnogram 0.0.9" }, "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "info@cert.vde.com", "DATE_PUBLIC": "2022-04-27T10:00:00.000Z", "ID": "CVE-2021-34589", "STATE": "PUBLIC", "TITLE": "Bender Charge Controller: RFID leak" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "CC612", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } }, { "product_name": "CC613", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } }, { "product_name": "ICC15xx", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } }, { "product_name": "ICC16xx", "version": { "version_data": [ { "version_affected": "\u003c", "version_name": "5.11.x", "version_value": "5.11.2" }, { "version_affected": "\u003c", "version_name": "5.12.x", "version_value": "5.12.5" }, { "version_affected": "\u003c", "version_name": "5.13.x", "version_value": "5.13.2" }, { "version_affected": "\u003c", "version_name": "5.20.x", "version_value": "5.20.2" } ] } } ] }, "vendor_name": "Bender / ebee" } ] } }, "credit": [ { "lang": "eng", "value": "Bender thanks the IT security researchers at OpenSource Security GmbH for their thorough and in-depth work. The issue was coordinated by CERT@VDE." } ], "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "In Bender/ebee Charge Controllers in multiple versions are prone to an RFID leak. The RFID of the last charge event can be read without authentication via the web interface." } ] }, "generator": { "engine": "Vulnogram 0.0.9" }, "impact": { "cvss": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" } }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-200 Information Exposure" } ] } ] }, "references": { "reference_data": [ { "name": "https://cert.vde.com/en/advisories/VDE-2021-047", "refsource": "CONFIRM", "url": "https://cert.vde.com/en/advisories/VDE-2021-047" } ] }, "source": { "advisory": "VDE-2021-047", "defect": [ "CERT@VDE#64088" ], "discovery": "EXTERNAL" } } } }, "cveMetadata": { "assignerOrgId": "270ccfa6-a436-4e77-922e-914ec3a9685c", "assignerShortName": "CERTVDE", "cveId": "CVE-2021-34589", "datePublished": "2022-04-27T15:15:27.151287Z", "dateReserved": "2021-06-10T00:00:00", "dateUpdated": "2024-09-16T21:08:59.841Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1" }