CVE-2019-19228
Severity CVSS v4.0:
Pending analysis
Type:
CWE-312
Cleartext Storage of Sensitive Information
Publication date:
04/12/2019
Last modified:
16/12/2019
Description
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:fronius:datamanager_box_2.0_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:datamanager_box_2.0:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:eco_25.0-3-s_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:eco_25.0-3-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:eco_27.0-3-s_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:eco_27.0-3-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_1.5-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_1.5-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_1.5-1_208-240_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_1.5-1_208-240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.0-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_2.0-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.0-1_208-240_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_2.0-1_208-240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.5-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



