PT-2021-12846 · Tesla+1 · Tesla Solarcity Solar Monitoring Gateway+1

Jake Valletta

+3

·

Published

2021-02-17

·

Updated

2021-07-21

·

CVE-2020-9306

CVSS v3.1

8.8

High

VectorAC:L/AV:A/A:H/C:H/I:H/PR:N/S:U/UI:N
Name of the Vulnerable Software and Affected Versions: Tesla SolarCity Solar Monitoring Gateway versions through 5.46.43
Description: The issue is related to the use of hard-coded credentials. Specifically, Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
Recommendations: For Tesla SolarCity Solar Monitoring Gateway versions through 5.46.43, consider removing or securely storing the hard-coded credentials in the .pyc file used by Digi ConnectPort X2e to mitigate the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Using Hardcoded Credentials

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9306

Affected Products

Digi Connectport X2E
Tesla Solarcity Solar Monitoring Gateway