Vulnerability Description
In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "security best practices" violation
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Victronenergy | Venus Os | <= 2.72 |
References
- https://github.com/victronenergy/venus/issues/836Third Party Advisory
- https://github.com/victronenergy/venus/issues/836Third Party Advisory
FAQ
What is CVE-2021-36797?
CVE-2021-36797 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device. NOTE: the vendor disagrees with the reporter's opinion about an alleged "securi...
How severe is CVE-2021-36797?
CVE-2021-36797 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-36797?
Check the references section above for vendor advisories and patch information. Affected products include: Victronenergy Venus Os.