PT-2021-21364 · Victron Energy · Victron Energy Venus Os

·

CVE-2021-36797

·

Published

2021-07-19

·

Updated

2024-08-04

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Victron Energy Venus OS versions through 2.72
Description The issue allows root access by default to anyone with physical access to the device, which may be considered a violation of security best practices. However, the vendor disagrees with this assessment.
Recommendations For Victron Energy Venus OS versions through 2.72, consider restricting physical access to the device to minimize the risk of unauthorized root access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-36797

Affected Products

Victron Energy Venus Os