Vulnerability Details CVE-2021-34590
In Bender/ebee Charge Controllers in multiple versions are prone to Cross-site Scripting. An authenticated attacker could write HTML Code into configuration values. These values are not properly escaped when displayed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.6%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-34590
-
-
-
cpe:2.3:o:bender:cc612_firmware:*
-
cpe:2.3:o:bender:cc612_firmware:5.11.0
-
cpe:2.3:o:bender:icc15xx_firmware:*