CVE-2012-5863
high · 10These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
10
CVSS
24.8%
EPSS (exploit prob.)
98th
EPSS percentile
2012-11-23
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-78CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sinapsitech | sinapsi_firmware | <= 2.0.2870 |
| sinapsitech | esolar_duo_photovoltaic_system_monitor | all versions |
| sinapsitech | esolar_light_photovoltaic_system_monitor | all versions |
| sinapsitech | esolar_photovoltaic_system_monitor | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
- http://www.exploit-db.com/exploits/21273/
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80200
- https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
- http://www.exploit-db.com/exploits/21273/
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80202
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-5863