CVE-2021-28910

HIGH

BAB TECHNOLOGIE eibPort V3 < 3.9.1 - Unauthenticated Server-Side Request Forgery

Title source: llm
STIX 2.1

Description

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attackers to request to any internal and external server.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://psytester.github.io/CVE-2021-28910

Scores

CVSS v3 7.5
EPSS 0.0113
EPSS Percentile 62.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (1)
bab-technologie/eibport_firmware < 3.9.1
Published Sep 09, 2021
Tracked Since Feb 18, 2026