PT-2021-12846 · Tesla+1 · Tesla Solarcity Solar Monitoring Gateway+1
Jake Valletta
+3
·
Published
2021-02-17
·
Updated
2021-07-21
·
CVE-2020-9306
CVSS v3.1
8.8
High
| Vector | AC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N |
Name of the Vulnerable Software and Affected Versions:
Tesla SolarCity Solar Monitoring Gateway versions through 5.46.43
Description:
The issue is related to the use of hard-coded credentials. Specifically, Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the
python user account.Recommendations:
For Tesla SolarCity Solar Monitoring Gateway versions through 5.46.43, consider removing or securely storing the hard-coded credentials in the .pyc file used by Digi ConnectPort X2e to mitigate the risk.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Using Hardcoded Credentials
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Digi Connectport X2E
Tesla Solarcity Solar Monitoring Gateway