CVE-2019-19228

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
04/12/2019
Last modified:
16/12/2019

Description

Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:fronius:datamanager_box_2.0_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:datamanager_box_2.0:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:eco_25.0-3-s_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:eco_25.0-3-s:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:eco_27.0-3-s_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:eco_27.0-3-s:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:galvo_1.5-1_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:galvo_1.5-1:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:galvo_1.5-1_208-240_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:galvo_1.5-1_208-240:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:galvo_2.0-1_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:galvo_2.0-1:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:galvo_2.0-1_208-240_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)
cpe:2.3:h:fronius:galvo_2.0-1_208-240:-:*:*:*:*:*:*:*
cpe:2.3:o:fronius:galvo_2.5-1_firmware:*:*:*:*:*:*:*:* 3.14.1 (excluding)