Description
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
Published: 2019-12-04
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-8854 Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
History

No history.

Subscriptions

Fronius Datamanager Box 2.0 Datamanager Box 2.0 Firmware Eco 25.0-3-s Eco 25.0-3-s Firmware Eco 27.0-3-s Eco 27.0-3-s Firmware Galvo 1.5-1 Galvo 1.5-1 208-240 Galvo 1.5-1 208-240 Firmware Galvo 1.5-1 Firmware Galvo 2.0-1 Galvo 2.0-1 208-240 Galvo 2.0-1 208-240 Firmware Galvo 2.0-1 Firmware Galvo 2.5-1 Galvo 2.5-1 208-240 Galvo 2.5-1 208-240 Firmware Galvo 2.5-1 Firmware Galvo 3.0-1 Galvo 3.0-1 Firmware Galvo 3.1-1 Galvo 3.1-1 208-240 Galvo 3.1-1 208-240 Firmware Galvo 3.1-1 Firmware Primo 10.0-1 208-240 Primo 10.0-1 208-240 Firmware Primo 11.4-1 208-240 Primo 11.4-1 208-240 Firmware Primo 12.5-1 208-240 Primo 12.5-1 208-240 Firmware Primo 15.0-1 208-240 Primo 15.0-1 208-240 Firmware Primo 3.0-1 Primo 3.0-1 Firmware Primo 3.5-1 Primo 3.5-1 Firmware Primo 3.6-1 Primo 3.6-1 Firmware Primo 3.8-1 208-240 Primo 3.8-1 208-240 Firmware Primo 4.0-1 Primo 4.0-1 Firmware Primo 4.6-1 Primo 4.6-1 Firmware Primo 5.0-1 Primo 5.0-1 208-240 Primo 5.0-1 208-240 Firmware Primo 5.0-1 Aus Primo 5.0-1 Aus Firmware Primo 5.0-1 Firmware Primo 5.0-1 Sc Primo 5.0-1 Sc Firmware Primo 6.0-1 Primo 6.0-1 208-240 Primo 6.0-1 208-240 Firmware Primo 6.0-1 Firmware Primo 7.6-1 208-240 Primo 7.6-1 208-240 Firmware Primo 8.2-1 Primo 8.2-1 208-240 Primo 8.2-1 208-240 Firmware Primo 8.2-1 Firmware Symo 10.0-3-m Symo 10.0-3-m-os Symo 10.0-3-m-os Firmware Symo 10.0-3-m Firmware Symo 10.0-3 208-240 Symo 10.0-3 208-240 Firmware Symo 10.0-3 480 Symo 10.0-3 480 Firmware Symo 12.0-3 208-240 Symo 12.0-3 208-240 Firmware Symo 12.5-3-m Symo 12.5-3-m Firmware Symo 12.5-3 480 Symo 12.5-3 480 Firmware Symo 15.0-3-m Symo 15.0-3-m Firmware Symo 15.0-3 107 Symo 15.0-3 107 Firmware Symo 15.0-3 480 Symo 15.0-3 480 Firmware Symo 17.5-3-m Symo 17.5-3-m Firmware Symo 17.5-3 480 Symo 17.5-3 480 Firmware Symo 20.0-3-m Symo 20.0-3-m Firmware Symo 20.0-3 480 Symo 20.0-3 480 Firmware Symo 22.7-3 480 Symo 22.7-3 480 Firmware Symo 24.0-3 480 Symo 24.0-3 480 Firmware Symo 3.0-3-m Symo 3.0-3-m Firmware Symo 3.0-3-s Symo 3.0-3-s Firmware Symo 3.7-3-m Symo 3.7-3-m Firmware Symo 3.7-3-s Symo 3.7-3-s Firmware Symo 4.5-3-m Symo 4.5-3-m Firmware Symo 4.5-3-s Symo 4.5-3-s Firmware Symo 5.0-3-m Symo 5.0-3-m Firmware Symo 6.0-3-m Symo 6.0-3-m Firmware Symo 7.0-3-m Symo 7.0-3-m Firmware Symo 8.2-3-m Symo 8.2-3-m Firmware Symo Advanced 10.0-3 208-240 Symo Advanced 10.0-3 208-240 Firmware Symo Advanced 12.0-3 208-240 Symo Advanced 12.0-3 208-240 Firmware Symo Advanced 15.0-3 480 Symo Advanced 15.0-3 480 Firmware Symo Advanced 20.0-3 480 Symo Advanced 20.0-3 480 Firmware Symo Advanced 22.7-3 480 Symo Advanced 22.7-3 480 Firmware Symo Advanced 24.0-3 480 Symo Advanced 24.0-3 480 Firmware Symo Hybrid 3.0-3-m Symo Hybrid 3.0-3-m Firmware Symo Hybrid 4.0-3-m Symo Hybrid 4.0-3-m Firmware Symo Hybrid 5.0-3-m Symo Hybrid 5.0-3-m Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T02:09:39.342Z

Reserved: 2019-11-22T00:00:00.000Z

Link: CVE-2019-19228

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-04T19:15:11.767

Modified: 2024-11-21T04:34:22.433

Link: CVE-2019-19228

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses