CVE-2019-19229
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
04/12/2019
Last modified:
17/06/2026
Description
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:fronius:datamanager_box_2.0_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:datamanager_box_2.0:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:eco_25.0-3-s_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:eco_25.0-3-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:eco_27.0-3-s_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:eco_27.0-3-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_1.5-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_1.5-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_1.5-1_208-240_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_1.5-1_208-240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.0-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_2.0-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.0-1_208-240_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_2.0-1_208-240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.5-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-Insecure-Communication-Path-Traversal.html
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-solar-inverter-series-cve-2019-19229-cve-2019-19228/
- https://seclists.org/bugtraq/2019/Dec/5
- http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-Insecure-Communication-Path-Traversal.html
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-solar-inverter-series-cve-2019-19229-cve-2019-19228/
- https://seclists.org/bugtraq/2019/Dec/5


