9.8

CVE-2019-19228

Exploit
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FroniusDatamanager Box 2.0 Firmware Version < 3.14.1
   FroniusDatamanager Box 2.0 Version-
FroniusEco 25.0-3-s Firmware Version < 3.14.1
   FroniusEco 25.0-3-s Version-
FroniusEco 27.0-3-s Firmware Version < 3.14.1
   FroniusEco 27.0-3-s Version-
FroniusGalvo 1.5-1 Firmware Version < 3.14.1
   FroniusGalvo 1.5-1 Version-
FroniusGalvo 1.5-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 1.5-1 208-240 Version-
FroniusGalvo 2.0-1 Firmware Version < 3.14.1
   FroniusGalvo 2.0-1 Version-
FroniusGalvo 2.0-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 2.0-1 208-240 Version-
FroniusGalvo 2.5-1 Firmware Version < 3.14.1
   FroniusGalvo 2.5-1 Version-
FroniusGalvo 2.5-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 2.5-1 208-240 Version-
FroniusGalvo 3.0-1 Firmware Version < 3.14.1
   FroniusGalvo 3.0-1 Version-
FroniusGalvo 3.1-1 Firmware Version < 3.14.1
   FroniusGalvo 3.1-1 Version-
FroniusGalvo 3.1-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 3.1-1 208-240 Version-
FroniusPrimo 10.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 10.0-1 208-240 Version-
FroniusPrimo 11.4-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 11.4-1 208-240 Version-
FroniusPrimo 12.5-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 12.5-1 208-240 Version-
FroniusPrimo 15.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 15.0-1 208-240 Version-
FroniusPrimo 3.0-1 Firmware Version < 3.14.1
   FroniusPrimo 3.0-1 Version-
FroniusPrimo 3.5-1 Firmware Version < 3.14.1
   FroniusPrimo 3.5-1 Version-
FroniusPrimo 3.6-1 Firmware Version < 3.14.1
   FroniusPrimo 3.6-1 Version-
FroniusPrimo 3.8-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 3.8-1 208-240 Version-
FroniusPrimo 4.0-1 Firmware Version < 3.14.1
   FroniusPrimo 4.0-1 Version-
FroniusPrimo 4.6-1 Firmware Version < 3.14.1
   FroniusPrimo 4.6-1 Version-
FroniusPrimo 5.0-1 Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 Version-
FroniusPrimo 5.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 208-240 Version-
FroniusPrimo 5.0-1 Aus Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 Aus Version-
FroniusPrimo 5.0-1 Sc Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 Sc Version-
FroniusPrimo 6.0-1 Firmware Version < 3.14.1
   FroniusPrimo 6.0-1 Version-
FroniusPrimo 6.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 6.0-1 208-240 Version-
FroniusPrimo 7.6-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 7.6-1 208-240 Version-
FroniusPrimo 8.2-1 Firmware Version < 3.14.1
   FroniusPrimo 8.2-1 Version-
FroniusPrimo 8.2-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 8.2-1 208-240 Version-
FroniusSymo 10.0-3-m Firmware Version < 3.14.1
   FroniusSymo 10.0-3-m Version-
FroniusSymo 10.0-3-m-os Firmware Version < 3.14.1
   FroniusSymo 10.0-3-m-os Version-
FroniusSymo 10.0-3 208-240 Firmware Version < 3.14.1
   FroniusSymo 10.0-3 208-240 Version-
FroniusSymo 10.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 10.0-3 480 Version-
FroniusSymo 12.0-3 208-240 Firmware Version < 3.14.1
   FroniusSymo 12.0-3 208-240 Version-
FroniusSymo 12.5-3-m Firmware Version < 3.14.1
   FroniusSymo 12.5-3-m Version-
FroniusSymo 12.5-3 480 Firmware Version < 3.14.1
   FroniusSymo 12.5-3 480 Version-
FroniusSymo 15.0-3-m Firmware Version < 3.14.1
   FroniusSymo 15.0-3-m Version-
FroniusSymo 15.0-3 107 Firmware Version < 3.14.1
   FroniusSymo 15.0-3 107 Version-
FroniusSymo 15.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 15.0-3 480 Version-
FroniusSymo 17.5-3-m Firmware Version < 3.14.1
   FroniusSymo 17.5-3-m Version-
FroniusSymo 17.5-3 480 Firmware Version < 3.14.1
   FroniusSymo 17.5-3 480 Version-
FroniusSymo 20.0-3-m Firmware Version < 3.14.1
   FroniusSymo 20.0-3-m Version-
FroniusSymo 20.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 20.0-3 480 Version-
FroniusSymo 22.7-3 480 Firmware Version < 3.14.1
   FroniusSymo 22.7-3 480 Version-
FroniusSymo 24.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 24.0-3 480 Version-
FroniusSymo 3.0-3-m Firmware Version < 3.14.1
   FroniusSymo 3.0-3-m Version-
FroniusSymo 3.0-3-s Firmware Version < 3.14.1
   FroniusSymo 3.0-3-s Version-
FroniusSymo 3.7-3-m Firmware Version < 3.14.1
   FroniusSymo 3.7-3-m Version-
FroniusSymo 3.7-3-s Firmware Version < 3.14.1
   FroniusSymo 3.7-3-s Version-
FroniusSymo 4.5-3-m Firmware Version < 3.14.1
   FroniusSymo 4.5-3-m Version-
FroniusSymo 4.5-3-s Firmware Version < 3.14.1
   FroniusSymo 4.5-3-s Version-
FroniusSymo 5.0-3-m Firmware Version < 3.14.1
   FroniusSymo 5.0-3-m Version-
FroniusSymo 6.0-3-m Firmware Version < 3.14.1
   FroniusSymo 6.0-3-m Version-
FroniusSymo 7.0-3-m Firmware Version < 3.14.1
   FroniusSymo 7.0-3-m Version-
FroniusSymo 8.2-3-m Firmware Version < 3.14.1
   FroniusSymo 8.2-3-m Version-
FroniusSymo Hybrid 3.0-3-m Firmware Version < 3.14.1
   FroniusSymo Hybrid 3.0-3-m Version-
FroniusSymo Hybrid 4.0-3-m Firmware Version < 3.14.1
   FroniusSymo Hybrid 4.0-3-m Version-
FroniusSymo Hybrid 5.0-3-m Firmware Version < 3.14.1
   FroniusSymo Hybrid 5.0-3-m Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.472
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.