CVE-2021-28914

MEDIUM

BAB TECHNOLOGIE GmbH eibPort V3 <3.9.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_misc
https://psytester.github.io/CVE-2021-28914

Scores

CVSS v3 6.5
EPSS 0.0099
EPSS Percentile 57.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-521
Status published
Products (1)
bab-technologie/eibport_firmware < 3.9.1
Published Sep 09, 2021
Tracked Since Feb 18, 2026