VulnerabilityModified
CVE-2021-36797
In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device.
MEDIUM 6.8EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "security best practices" violation
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Affected
- victronenergy/venus os
- Source
- cve@mitre.org
References
- https://github.com/victronenergy/venus/issues/836Third Party Advisory
- https://github.com/victronenergy/venus/issues/836Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.