These Sinapsi devices do not check for special elements in commands sent
to the system. By accessing certain pages with administrative privileges
that do not require authentication within the device, attackers can
execute arbitrary, unexpected, or dangerous commands directly onto the
operating system.
References
Configurations
Configuration 1 (hide)
AND |
|
History
08 Jul 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-78 | |
References |
|
|
Summary | (en) These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system. |
21 Nov 2024, 01:45
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html - Exploit | |
References | () http://www.exploit-db.com/exploits/21273/ - Exploit | |
References | () http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88 - | |
References | () http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf - US Government Resource | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/80202 - |
Information
Published : 2012-11-23 12:09
Updated : 2025-07-08 16:15
NVD link : CVE-2012-5863
Mitre link : CVE-2012-5863
CVE.ORG link : CVE-2012-5863
JSON object : View
Products Affected
sinapsitech
- sinapsi_firmware
- esolar_light_photovoltaic_system_monitor
- esolar_duo_photovoltaic_system_monitor
- esolar_photovoltaic_system_monitor