CVE-2024-21881
Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x
Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/S:P/AU:Y/R:I/V:C/RE:H
Productos afectados
Enphase · Envoy¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →