Lucene search

K
cve[email protected]CVE-2023-32274
HistoryJun 20, 2023 - 8:15 p.m.

CVE-2023-32274

2023-06-2020:15:09
CWE-798
web.nvd.nist.gov
10
cve-2023-32274
enphase installer toolkit
hard coded credentials
android application
vulnerability
nvd

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.4%

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.

Affected configurations

NVD
Node
enphaseinstaller_toolkitMatch3.27.0

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Enphase Installer Toolkit",
    "vendor": "Enphase ",
    "versions": [
      {
        "status": "affected",
        "version": "3.27.0"
      }
    ]
  }
]

8.6 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.4%

Related for CVE-2023-32274