CVE-2021-28914

MEDIUM

BAB TECHNOLOGIE GmbH eibPort V3 <3.9.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow the user to set a weak password because the strength is shown in configuration tool, but finally not enforced. This is usable and part of an attack chain to gain SSH root access.

Scores

CVSS v3 6.5
EPSS 0.0057
EPSS Percentile 68.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-521
Status published
Products (1)
bab-technologie/eibport_firmware < 3.9.1
Published Sep 09, 2021
Tracked Since Feb 18, 2026