CVE-2023-32274

Severity CVSS v4.0:
Pending analysis
Type:
CWE-798 Use of Hard-coded Credentials
Publication date:
20/06/2023
Last modified:
28/06/2023

Description

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:enphase:installer_toolkit:3.27.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools