6.5
CVE-2019-19229
- EPSS 2.31%
- Veröffentlicht 04.12.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Fronius ≫ Datamanager Box 2.0 Firmware Version < 3.14.1
Fronius ≫ Eco 25.0-3-s Firmware Version < 3.14.1
Fronius ≫ Eco 27.0-3-s Firmware Version < 3.14.1
Fronius ≫ Galvo 1.5-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 1.5-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.0-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.5-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 2.5-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Galvo 3.0-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 3.1-1 Firmware Version < 3.14.1
Fronius ≫ Galvo 3.1-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 10.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 11.4-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 12.5-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 15.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 3.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 3.5-1 Firmware Version < 3.14.1
Fronius ≫ Primo 3.6-1 Firmware Version < 3.14.1
Fronius ≫ Primo 3.8-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 4.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 4.6-1 Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 Aus Firmware Version < 3.14.1
Fronius ≫ Primo 5.0-1 Sc Firmware Version < 3.14.1
Fronius ≫ Primo 6.0-1 Firmware Version < 3.14.1
Fronius ≫ Primo 6.0-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 7.6-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Primo 8.2-1 Firmware Version < 3.14.1
Fronius ≫ Primo 8.2-1 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3-m-os Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo 10.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 12.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo 12.5-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 12.5-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 15.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 15.0-3 107 Firmware Version < 3.14.1
Fronius ≫ Symo 15.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 17.5-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 17.5-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 20.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 20.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 22.7-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 24.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo 3.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 3.0-3-s Firmware Version < 3.14.1
Fronius ≫ Symo 3.7-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 3.7-3-s Firmware Version < 3.14.1
Fronius ≫ Symo 4.5-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 4.5-3-s Firmware Version < 3.14.1
Fronius ≫ Symo 5.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 6.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 7.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo 8.2-3-m Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 10.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 12.0-3 208-240 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 15.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 20.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 22.7-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Advanced 24.0-3 480 Firmware Version < 3.14.1
Fronius ≫ Symo Hybrid 3.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo Hybrid 4.0-3-m Firmware Version < 3.14.1
Fronius ≫ Symo Hybrid 5.0-3-m Firmware Version < 3.14.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.31% | 0.812 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-Insecure-Communication-Path-Traversal.html
https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-solar-inverter-series-cve-2019-19229-cve-2019-19228/
https://seclists.org/bugtraq/2019/Dec/5