PT-2019-15784 · Fronius · Fronius Solar Inverter

T. Weber

·

Publicado

2019-12-04

·

Atualizado

2019-12-16

·

CVE-2019-19228

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Fronius Solar Inverter devices versions prior to 3.14.1 (HM 1.12.1)
Description The issue allows attackers to bypass authentication because the password for the today account is stored in the /tmp/web users.conf file.
Recommendations For versions prior to 3.14.1 (HM 1.12.1), update to version 3.14.1 (HM 1.12.1) or later to resolve the issue.

Exploit

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-19228

Produtos afetados

Fronius Solar Inverter