PT-2023-29965 · Unknown · Solar-Log Base 15 Firmware
Mesut Cetin
+1
·
Published
2023-12-29
·
Updated
2024-11-11
·
CVE-2023-46344
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Solar-Log Base 15 Firmware version 6.0.1 Build 161
Description
A stored cross-site scripting (XSS) vulnerability in the switch group function under the
/#ilang=DE&b=c smartenergy swgroups endpoint in the web portal allows an attacker to escalate their privileges. This can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks.Recommendations
For Solar-Log Base 15 Firmware version 6.0.1 Build 161, update to a version that includes the fix, as stated by the vendor that the vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000.
As a temporary workaround, consider restricting access to the switch group function under the
/#ilang=DE&b=c smartenergy swgroups endpoint in the web portal until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solar-Log Base 15 Firmware