9.8
CVE-2019-19228
- EPSS 0.24%
- Veröffentlicht 04.12.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fronius ≫ Datamanager Box 2.0 Firmware Version < 3.14.1
Fronius ≫ Eco 25.0-3-s Firmware Version < 3.14.1
Fronius ≫ Eco 27.0-3-s Firmware Version < 3.14.1
Fronius ≫ Galvo 1.5-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 1.5-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.0-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.5-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.5-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Galvo 3.0-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 3.1-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 3.1-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 10.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 11.4-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 12.5-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 15.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 3.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 3.5-1 Firmware Version < 3.14.1
Fronius ≫ Primo 3.6-1 Firmware Version < 3.14.1
Fronius ≫ Primo 3.8-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 4.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 4.6-1 Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 Aus Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 Sc Firmware Version < 3.14.1
Fronius ≫ Primo 6.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 6.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 7.6-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 8.2-1 Firmware Version < 3.14.1
Fronius ≫ Primo 8.2-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3-m-os Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 12.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo 12.5-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 12.5-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 15.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 15.0-3 107 Firmware Version < 3.14.1
Fronius ≫ Symo 15.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 17.5-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 17.5-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 20.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 20.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 22.7-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 24.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 3.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 3.0-3-s Firmware Version < 3.14.1
Fronius ≫ Symo 3.7-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 3.7-3-s Firmware Version < 3.14.1
Fronius ≫ Symo 4.5-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 4.5-3-s Firmware Version < 3.14.1
Fronius ≫ Symo 5.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 6.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 7.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 8.2-3-m Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 10.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 12.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 15.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 20.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 22.7-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 24.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Hybrid 3.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo Hybrid 4.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo Hybrid 5.0-3-m Firmware Version < 3.14.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.472 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.