Записи Enphase
15 опубликованных записей вендора enphase.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 26,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-798 Use of Hard-coded Credentials2
- CWE-326 Inadequate Encryption Strength1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2019-7678Эксплойта нет | A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 888enphase · envoy · CWE-22 | Критическая9,8 | — | 2,5 % | 9 февр. 2019 г. |
40В плане | CVE-2020-25753Эксплойта нет | An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.enphase · envoy firmware | Критическая9,8 | — | 2,2 % | 16 июн. 2021 г. |
39Наблюдать | CVE-2023-33869Proof of concept | Enphase Envoy OS Command Injectionenphase · envoy firmware · CWE-78 | Критическая9,8 | — | 1,1 % | 20 июн. 2023 г. |
37Наблюдать | CVE-2024-21876Эксплойта нет | Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225enphase · iq gateway firmware · CWE-22 | Критическая9,3 | — | 0,8 % | 12 авг. 2024 г. |
36Наблюдать | CVE-2020-25755Эксплойта нет | An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices.enphase · envoy firmware · CWE-78 | Высокая8,8 | — | 3,1 % | 16 июн. 2021 г. |
36Наблюдать | CVE-2024-21878Эксплойта нет | Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.xenphase · iq gateway firmware · CWE-77 | Критическая9,2 | — | 1,4 % | 12 авг. 2024 г. |
36Наблюдать | CVE-2024-21877Эксплойта нет | Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225enphase · iq gateway firmware · CWE-22 | Критическая9,2 | — | 0,8 % | 12 авг. 2024 г. |
35Наблюдать | CVE-2024-21879Эксплойта нет | URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225enphase · iq gateway firmware · CWE-77 | Высокая8,7 | — | 2,5 % | 12 авг. 2024 г. |
35Наблюдать | CVE-2024-21880Эксплойта нет | URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.xenphase · iq gateway firmware · CWE-77 | Высокая8,6 | — | 2,4 % | 12 авг. 2024 г. |
34Наблюдать | CVE-2024-21881Эксплойта нет | Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.xenphase · envoy · CWE-326 | Высокая8,6 | — | 0,3 % | 12 авг. 2024 г. |
30Наблюдать | CVE-2020-25754Эксплойта нет | An issue was discovered on Enphase Envoy R3.x and D4.x devices.enphase · envoy firmware · CWE-916 | Высокая7,5 | — | 1,4 % | 16 июн. 2021 г. |
30Наблюдать | CVE-2023-32274Эксплойта нет | Enphase Installer Toolkit Android App Use of Hard-coded Credentialsenphase · installer toolkit · CWE-798 | Высокая7,5 | — | 0,6 % | 20 июн. 2023 г. |
29Наблюдать | CVE-2019-7676Эксплойта нет | A weak password vulnerability was discovered in Enphase Envoy R3.*.*.enphase · envoy · CWE-521 | Высокая7,2 | — | 1,7 % | 9 февр. 2019 г. |
24Наблюдать | CVE-2019-7677Эксплойта нет | XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.enphase · envoy · CWE-79 | Средняя6,1 | — | 0,9 % | 9 февр. 2019 г. |
21Наблюдать | CVE-2020-25752Эксплойта нет | An issue was discovered on Enphase Envoy R3.x and D4.x devices.enphase · envoy firmware · CWE-798 | Средняя5,3 | — | 1,6 % | 16 июн. 2021 г. |
- CVE-2019-767840В плане
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 888
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %enphase · envoy9 февр. 2019 г.
- CVE-2020-2575340В плане
An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %enphase · envoy firmware16 июн. 2021 г.
- CVE-2023-3386939Наблюдать
Enphase Envoy OS Command Injection
КритическаяCVSS 9,8Proof of conceptEPSS 1 %enphase · envoy firmware20 июн. 2023 г.
- CVE-2024-2187637Наблюдать
Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %enphase · iq gateway firmware12 авг. 2024 г.
- CVE-2020-2575536Наблюдать
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %enphase · envoy firmware16 июн. 2021 г.
- CVE-2024-2187836Наблюдать
Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %enphase · iq gateway firmware12 авг. 2024 г.
- CVE-2024-2187736Наблюдать
Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225
КритическаяCVSS 9,2Эксплойта нетEPSS 1 %enphase · iq gateway firmware12 авг. 2024 г.
- CVE-2024-2187935Наблюдать
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225
ВысокаяCVSS 8,7Эксплойта нетEPSS 2 %enphase · iq gateway firmware12 авг. 2024 г.
- CVE-2024-2188035Наблюдать
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.x
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %enphase · iq gateway firmware12 авг. 2024 г.
- CVE-2024-2188134Наблюдать
Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %enphase · envoy12 авг. 2024 г.
- CVE-2020-2575430Наблюдать
An issue was discovered on Enphase Envoy R3.x and D4.x devices.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %enphase · envoy firmware16 июн. 2021 г.
- CVE-2023-3227430Наблюдать
Enphase Installer Toolkit Android App Use of Hard-coded Credentials
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %enphase · installer toolkit20 июн. 2023 г.
- CVE-2019-767629Наблюдать
A weak password vulnerability was discovered in Enphase Envoy R3.*.*.
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %enphase · envoy9 февр. 2019 г.
- CVE-2019-767724Наблюдать
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %enphase · envoy9 февр. 2019 г.
- CVE-2020-2575221Наблюдать
An issue was discovered on Enphase Envoy R3.x and D4.x devices.
СредняяCVSS 5,3Эксплойта нетEPSS 2 %enphase · envoy firmware16 июн. 2021 г.