PT-2021-21364 · Victron Energy · Victron Energy Venus Os
Deosrc
·
Published
2021-07-19
·
Updated
2024-08-04
·
CVE-2021-36797
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Victron Energy Venus OS versions through 2.72
Description
The issue allows root access by default to anyone with physical access to the device, which may be considered a violation of security best practices. However, the vendor disagrees with this assessment.
Recommendations
For Victron Energy Venus OS versions through 2.72, consider restricting physical access to the device to minimize the risk of unauthorized root access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Victron Energy Venus Os