10
CVE-2012-5862
- EPSS 18.26%
- Veröffentlicht 23.11.2012 12:09:58
- Zuletzt bearbeitet 08.07.2025 16:15:26
- Quelle ics-cert@hq.dhs.gov
- CVE-Watchlists
- Unerledigt
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sinapsitech ≫ Sinapsi Firmware Version <= 2.0.2870
Sinapsitech ≫ Esolar Photovoltaic System Monitor Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 18.26% | 0.95 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
| ics-cert@hq.dhs.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-259 Use of Hard-coded Password
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.