CVE-2019-19229
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
04/12/2019
Last modified:
16/12/2019
Description
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:fronius:datamanager_box_2.0_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:datamanager_box_2.0:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:eco_25.0-3-s_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:eco_25.0-3-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:eco_27.0-3-s_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:eco_27.0-3-s:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_1.5-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_1.5-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_1.5-1_208-240_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_1.5-1_208-240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.0-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_2.0-1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.0-1_208-240_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) | |
| cpe:2.3:h:fronius:galvo_2.0-1_208-240:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:fronius:galvo_2.5-1_firmware:*:*:*:*:*:*:*:* | 3.14.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



