Enphase records
15 published records for vendor enphase.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 26.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-798 Use of Hard-coded Credentials2
- CWE-326 Inadequate Encryption Strength1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
15 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2019-7678No exploit | A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 888enphase · envoy · CWE-22 | Critical9.8 | — | 2.5% | Feb 9, 2019 |
40Plan | CVE-2020-25753No exploit | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.enphase · envoy firmware | Critical9.8 | — | 2.2% | Jun 16, 2021 |
39Monitor | CVE-2023-33869Proof of concept | Enphase Envoy OS Command Injectionenphase · envoy firmware · CWE-78 | Critical9.8 | — | 1.1% | Jun 20, 2023 |
37Monitor | CVE-2024-21876No exploit | Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225enphase · iq gateway firmware · CWE-22 | Critical9.3 | — | 0.8% | Aug 12, 2024 |
36Monitor | CVE-2020-25755No exploit | An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices.enphase · envoy firmware · CWE-78 | High8.8 | — | 3.1% | Jun 16, 2021 |
36Monitor | CVE-2024-21878No exploit | Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.xenphase · iq gateway firmware · CWE-77 | Critical9.2 | — | 1.4% | Aug 12, 2024 |
36Monitor | CVE-2024-21877No exploit | Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225enphase · iq gateway firmware · CWE-22 | Critical9.2 | — | 0.8% | Aug 12, 2024 |
35Monitor | CVE-2024-21879No exploit | URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225enphase · iq gateway firmware · CWE-77 | High8.7 | — | 2.5% | Aug 12, 2024 |
35Monitor | CVE-2024-21880No exploit | URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.xenphase · iq gateway firmware · CWE-77 | High8.6 | — | 2.4% | Aug 12, 2024 |
34Monitor | CVE-2024-21881No exploit | Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.xenphase · envoy · CWE-326 | High8.6 | — | 0.3% | Aug 12, 2024 |
30Monitor | CVE-2020-25754No exploit | An issue was discovered on Enphase Envoy R3.x and D4.x devices.enphase · envoy firmware · CWE-916 | High7.5 | — | 1.4% | Jun 16, 2021 |
30Monitor | CVE-2023-32274No exploit | Enphase Installer Toolkit Android App Use of Hard-coded Credentialsenphase · installer toolkit · CWE-798 | High7.5 | — | 0.6% | Jun 20, 2023 |
29Monitor | CVE-2019-7676No exploit | A weak password vulnerability was discovered in Enphase Envoy R3.*.*.enphase · envoy · CWE-521 | High7.2 | — | 1.7% | Feb 9, 2019 |
24Monitor | CVE-2019-7677No exploit | XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.enphase · envoy · CWE-79 | Medium6.1 | — | 0.9% | Feb 9, 2019 |
21Monitor | CVE-2020-25752No exploit | An issue was discovered on Enphase Envoy R3.x and D4.x devices.enphase · envoy firmware · CWE-798 | Medium5.3 | — | 1.6% | Jun 16, 2021 |
- CVE-2019-767840Plan
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 888
CriticalCVSS 9.8No exploitEPSS 2%enphase · envoyFeb 9, 2019
- CVE-2020-2575340Plan
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.
CriticalCVSS 9.8No exploitEPSS 2%enphase · envoy firmwareJun 16, 2021
- CVE-2023-3386939Monitor
Enphase Envoy OS Command Injection
CriticalCVSS 9.8Proof of conceptEPSS 1%enphase · envoy firmwareJun 20, 2023
- CVE-2024-2187637Monitor
Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225
CriticalCVSS 9.3No exploitEPSS 1%enphase · iq gateway firmwareAug 12, 2024
- CVE-2020-2575536Monitor
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices.
HighCVSS 8.8No exploitEPSS 3%enphase · envoy firmwareJun 16, 2021
- CVE-2024-2187836Monitor
Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x
CriticalCVSS 9.2No exploitEPSS 1%enphase · iq gateway firmwareAug 12, 2024
- CVE-2024-2187736Monitor
Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225
CriticalCVSS 9.2No exploitEPSS 1%enphase · iq gateway firmwareAug 12, 2024
- CVE-2024-2187935Monitor
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225
HighCVSS 8.7No exploitEPSS 2%enphase · iq gateway firmwareAug 12, 2024
- CVE-2024-2188035Monitor
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.x
HighCVSS 8.6No exploitEPSS 2%enphase · iq gateway firmwareAug 12, 2024
- CVE-2024-2188134Monitor
Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x
HighCVSS 8.6No exploitEPSS 0%enphase · envoyAug 12, 2024
- CVE-2020-2575430Monitor
An issue was discovered on Enphase Envoy R3.x and D4.x devices.
HighCVSS 7.5No exploitEPSS 1%enphase · envoy firmwareJun 16, 2021
- CVE-2023-3227430Monitor
Enphase Installer Toolkit Android App Use of Hard-coded Credentials
HighCVSS 7.5No exploitEPSS 1%enphase · installer toolkitJun 20, 2023
- CVE-2019-767629Monitor
A weak password vulnerability was discovered in Enphase Envoy R3.*.*.
HighCVSS 7.2No exploitEPSS 2%enphase · envoyFeb 9, 2019
- CVE-2019-767724Monitor
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
MediumCVSS 6.1No exploitEPSS 1%enphase · envoyFeb 9, 2019
- CVE-2020-2575221Monitor
An issue was discovered on Enphase Envoy R3.x and D4.x devices.
MediumCVSS 5.3No exploitEPSS 2%enphase · envoy firmwareJun 16, 2021