6.5

CVE-2019-19229

Exploit
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
FroniusDatamanager Box 2.0 Firmware Version < 3.14.1
   FroniusDatamanager Box 2.0 Version-
FroniusEco 25.0-3-s Firmware Version < 3.14.1
   FroniusEco 25.0-3-s Version-
FroniusEco 27.0-3-s Firmware Version < 3.14.1
   FroniusEco 27.0-3-s Version-
FroniusGalvo 1.5-1 Firmware Version < 3.14.1
   FroniusGalvo 1.5-1 Version-
FroniusGalvo 1.5-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 1.5-1 208-240 Version-
FroniusGalvo 2.0-1 Firmware Version < 3.14.1
   FroniusGalvo 2.0-1 Version-
FroniusGalvo 2.0-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 2.0-1 208-240 Version-
FroniusGalvo 2.5-1 Firmware Version < 3.14.1
   FroniusGalvo 2.5-1 Version-
FroniusGalvo 2.5-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 2.5-1 208-240 Version-
FroniusGalvo 3.0-1 Firmware Version < 3.14.1
   FroniusGalvo 3.0-1 Version-
FroniusGalvo 3.1-1 Firmware Version < 3.14.1
   FroniusGalvo 3.1-1 Version-
FroniusGalvo 3.1-1 208-240 Firmware Version < 3.14.1
   FroniusGalvo 3.1-1 208-240 Version-
FroniusPrimo 10.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 10.0-1 208-240 Version-
FroniusPrimo 11.4-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 11.4-1 208-240 Version-
FroniusPrimo 12.5-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 12.5-1 208-240 Version-
FroniusPrimo 15.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 15.0-1 208-240 Version-
FroniusPrimo 3.0-1 Firmware Version < 3.14.1
   FroniusPrimo 3.0-1 Version-
FroniusPrimo 3.5-1 Firmware Version < 3.14.1
   FroniusPrimo 3.5-1 Version-
FroniusPrimo 3.6-1 Firmware Version < 3.14.1
   FroniusPrimo 3.6-1 Version-
FroniusPrimo 3.8-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 3.8-1 208-240 Version-
FroniusPrimo 4.0-1 Firmware Version < 3.14.1
   FroniusPrimo 4.0-1 Version-
FroniusPrimo 4.6-1 Firmware Version < 3.14.1
   FroniusPrimo 4.6-1 Version-
FroniusPrimo 5.0-1 Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 Version-
FroniusPrimo 5.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 208-240 Version-
FroniusPrimo 5.0-1 Aus Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 Aus Version-
FroniusPrimo 5.0-1 Sc Firmware Version < 3.14.1
   FroniusPrimo 5.0-1 Sc Version-
FroniusPrimo 6.0-1 Firmware Version < 3.14.1
   FroniusPrimo 6.0-1 Version-
FroniusPrimo 6.0-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 6.0-1 208-240 Version-
FroniusPrimo 7.6-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 7.6-1 208-240 Version-
FroniusPrimo 8.2-1 Firmware Version < 3.14.1
   FroniusPrimo 8.2-1 Version-
FroniusPrimo 8.2-1 208-240 Firmware Version < 3.14.1
   FroniusPrimo 8.2-1 208-240 Version-
FroniusSymo 10.0-3-m Firmware Version < 3.14.1
   FroniusSymo 10.0-3-m Version-
FroniusSymo 10.0-3-m-os Firmware Version < 3.14.1
   FroniusSymo 10.0-3-m-os Version-
FroniusSymo 10.0-3 208-240 Firmware Version < 3.14.1
   FroniusSymo 10.0-3 208-240 Version-
FroniusSymo 10.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 10.0-3 480 Version-
FroniusSymo 12.0-3 208-240 Firmware Version < 3.14.1
   FroniusSymo 12.0-3 208-240 Version-
FroniusSymo 12.5-3-m Firmware Version < 3.14.1
   FroniusSymo 12.5-3-m Version-
FroniusSymo 12.5-3 480 Firmware Version < 3.14.1
   FroniusSymo 12.5-3 480 Version-
FroniusSymo 15.0-3-m Firmware Version < 3.14.1
   FroniusSymo 15.0-3-m Version-
FroniusSymo 15.0-3 107 Firmware Version < 3.14.1
   FroniusSymo 15.0-3 107 Version-
FroniusSymo 15.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 15.0-3 480 Version-
FroniusSymo 17.5-3-m Firmware Version < 3.14.1
   FroniusSymo 17.5-3-m Version-
FroniusSymo 17.5-3 480 Firmware Version < 3.14.1
   FroniusSymo 17.5-3 480 Version-
FroniusSymo 20.0-3-m Firmware Version < 3.14.1
   FroniusSymo 20.0-3-m Version-
FroniusSymo 20.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 20.0-3 480 Version-
FroniusSymo 22.7-3 480 Firmware Version < 3.14.1
   FroniusSymo 22.7-3 480 Version-
FroniusSymo 24.0-3 480 Firmware Version < 3.14.1
   FroniusSymo 24.0-3 480 Version-
FroniusSymo 3.0-3-m Firmware Version < 3.14.1
   FroniusSymo 3.0-3-m Version-
FroniusSymo 3.0-3-s Firmware Version < 3.14.1
   FroniusSymo 3.0-3-s Version-
FroniusSymo 3.7-3-m Firmware Version < 3.14.1
   FroniusSymo 3.7-3-m Version-
FroniusSymo 3.7-3-s Firmware Version < 3.14.1
   FroniusSymo 3.7-3-s Version-
FroniusSymo 4.5-3-m Firmware Version < 3.14.1
   FroniusSymo 4.5-3-m Version-
FroniusSymo 4.5-3-s Firmware Version < 3.14.1
   FroniusSymo 4.5-3-s Version-
FroniusSymo 5.0-3-m Firmware Version < 3.14.1
   FroniusSymo 5.0-3-m Version-
FroniusSymo 6.0-3-m Firmware Version < 3.14.1
   FroniusSymo 6.0-3-m Version-
FroniusSymo 7.0-3-m Firmware Version < 3.14.1
   FroniusSymo 7.0-3-m Version-
FroniusSymo 8.2-3-m Firmware Version < 3.14.1
   FroniusSymo 8.2-3-m Version-
FroniusSymo Hybrid 3.0-3-m Firmware Version < 3.14.1
   FroniusSymo Hybrid 3.0-3-m Version-
FroniusSymo Hybrid 4.0-3-m Firmware Version < 3.14.1
   FroniusSymo Hybrid 4.0-3-m Version-
FroniusSymo Hybrid 5.0-3-m Firmware Version < 3.14.1
   FroniusSymo Hybrid 5.0-3-m Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.7% 0.711
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.