ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-34601
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials.

In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender charge controller CC612 in version 5.20.1 and below is prone to hardcoded ssh credentials. An attacker may use the password to gain administrative access to the web-UI.

NVD description · AI analysis pending
9.8
group max
1%
  • bender cc612 firmware
  • bender icc15xx firmware
CVE-2021-34587
In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash.

In Bender/ebee Charge Controllers in multiple versions a long URL could lead to webserver crash. The URL is used as input of an sprintf to a stack variable.

NVD description · AI analysis pending
5.3<1%
  • ibm ibm rational lifecycle integration adapter for windchill
  • ibm cc612 firmware
  • ibm cc613 firmware
  • +1 more
CVE-2019-19885
In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system.

In Bender COMTRAXX, user authorization is validated for most, but not all, routes in the system. A user with knowledge about the routes can read and write configuration data without prior authorization. This affects COM465IP, COM465DP, COM465ID, CP700, CP907, and CP915 devices before 4.2.0.

NVD description · AI analysis pending
9.1<1%
  • bender com465ip firmware
  • bender com465dp firmware
  • bender com465id firmware
  • +1 more