CVE-2019-19228

Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:fronius:datamanager_box_2.0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:datamanager_box_2.0:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:fronius:eco_25.0-3-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:eco_25.0-3-s:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:fronius:eco_27.0-3-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:eco_27.0-3-s:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:fronius:galvo_1.5-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_1.5-1:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:fronius:galvo_1.5-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_1.5-1_208-240:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:fronius:galvo_2.0-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_2.0-1:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:fronius:galvo_2.0-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_2.0-1_208-240:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:fronius:galvo_2.5-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_2.5-1:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:fronius:galvo_2.5-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_2.5-1_208-240:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:fronius:galvo_3.0-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_3.0-1:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:fronius:galvo_3.1-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_3.1-1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:fronius:galvo_3.1-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:galvo_3.1-1_208-240:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:fronius:primo_10.0-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_10.0-1_208-240:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:fronius:primo_11.4-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_11.4-1_208-240:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:fronius:primo_12.5-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_12.5-1_208-240:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:fronius:primo_15.0-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_15.0-1_208-240:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:fronius:primo_3.0-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_3.0-1:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:fronius:primo_3.5-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_3.5-1:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:fronius:primo_3.6-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_3.6-1:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:fronius:primo_3.8-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_3.8-1_208-240:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:fronius:primo_4.0-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_4.0-1:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:fronius:primo_4.6-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_4.6-1:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:fronius:primo_5.0-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_5.0-1:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:fronius:primo_5.0-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_5.0-1_208-240:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:fronius:primo_5.0-1_aus_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_5.0-1_aus:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:fronius:primo_5.0-1_sc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_5.0-1_sc:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:fronius:primo_6.0-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_6.0-1:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:fronius:primo_6.0-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_6.0-1_208-240:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:fronius:primo_7.6-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_7.6-1_208-240:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:fronius:primo_8.2-1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_8.2-1:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:fronius:primo_8.2-1_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:primo_8.2-1_208-240:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:fronius:symo_10.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_10.0-3-m:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:fronius:symo_10.0-3-m-os_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_10.0-3-m-os:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:fronius:symo_10.0-3_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_10.0-3_208-240:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:fronius:symo_10.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_10.0-3_480:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:fronius:symo_12.0-3_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_12.0-3_208-240:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:fronius:symo_12.5-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_12.5-3-m:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:fronius:symo_12.5-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_12.5-3_480:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:fronius:symo_15.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_15.0-3-m:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:fronius:symo_15.0-3_107_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_15.0-3_107:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:fronius:symo_15.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_15.0-3_480:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:fronius:symo_17.5-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_17.5-3-m:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:fronius:symo_17.5-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_17.5-3_480:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:fronius:symo_20.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_20.0-3-m:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:fronius:symo_20.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_20.0-3_480:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:fronius:symo_22.7-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_22.7-3_480:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:fronius:symo_24.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_24.0-3_480:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:fronius:symo_3.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_3.0-3-m:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:fronius:symo_3.0-3-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_3.0-3-s:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:fronius:symo_3.7-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_3.7-3-m:-:*:*:*:*:*:*:*

Configuration 51 (hide)

AND
cpe:2.3:o:fronius:symo_3.7-3-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_3.7-3-s:-:*:*:*:*:*:*:*

Configuration 52 (hide)

AND
cpe:2.3:o:fronius:symo_4.5-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_4.5-3-m:-:*:*:*:*:*:*:*

Configuration 53 (hide)

AND
cpe:2.3:o:fronius:symo_4.5-3-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_4.5-3-s:-:*:*:*:*:*:*:*

Configuration 54 (hide)

AND
cpe:2.3:o:fronius:symo_5.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_5.0-3-m:-:*:*:*:*:*:*:*

Configuration 55 (hide)

AND
cpe:2.3:o:fronius:symo_6.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_6.0-3-m:-:*:*:*:*:*:*:*

Configuration 56 (hide)

AND
cpe:2.3:o:fronius:symo_7.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_7.0-3-m:-:*:*:*:*:*:*:*

Configuration 57 (hide)

AND
cpe:2.3:o:fronius:symo_8.2-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_8.2-3-m:-:*:*:*:*:*:*:*

Configuration 58 (hide)

AND
cpe:2.3:o:fronius:symo_advanced_10.0-3_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_advanced_10.0-3_208-240:-:*:*:*:*:*:*:*

Configuration 59 (hide)

AND
cpe:2.3:o:fronius:symo_advanced_12.0-3_208-240_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_advanced_12.0-3_208-240:-:*:*:*:*:*:*:*

Configuration 60 (hide)

AND
cpe:2.3:o:fronius:symo_advanced_15.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_advanced_15.0-3_480:-:*:*:*:*:*:*:*

Configuration 61 (hide)

AND
cpe:2.3:o:fronius:symo_advanced_20.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_advanced_20.0-3_480:-:*:*:*:*:*:*:*

Configuration 62 (hide)

AND
cpe:2.3:o:fronius:symo_advanced_22.7-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_advanced_22.7-3_480:-:*:*:*:*:*:*:*

Configuration 63 (hide)

AND
cpe:2.3:o:fronius:symo_advanced_24.0-3_480_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_advanced_24.0-3_480:-:*:*:*:*:*:*:*

Configuration 64 (hide)

AND
cpe:2.3:o:fronius:symo_hybrid_3.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_hybrid_3.0-3-m:-:*:*:*:*:*:*:*

Configuration 65 (hide)

AND
cpe:2.3:o:fronius:symo_hybrid_4.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_hybrid_4.0-3-m:-:*:*:*:*:*:*:*

Configuration 66 (hide)

AND
cpe:2.3:o:fronius:symo_hybrid_5.0-3-m_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:fronius:symo_hybrid_5.0-3-m:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:34

Type Values Removed Values Added
References () http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-Insecure-Communication-Path-Traversal.html - Exploit, Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-Insecure-Communication-Path-Traversal.html - Exploit, Third Party Advisory, VDB Entry
References () https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-solar-inverter-series-cve-2019-19229-cve-2019-19228/ - Exploit, Third Party Advisory () https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-solar-inverter-series-cve-2019-19229-cve-2019-19228/ - Exploit, Third Party Advisory
References () https://seclists.org/bugtraq/2019/Dec/5 - Exploit, Mailing List, Third Party Advisory () https://seclists.org/bugtraq/2019/Dec/5 - Exploit, Mailing List, Third Party Advisory

Information

Published : 2019-12-04 19:15

Updated : 2024-11-21 04:34


NVD link : CVE-2019-19228

Mitre link : CVE-2019-19228

CVE.ORG link : CVE-2019-19228


JSON object : View

Products Affected

fronius

  • primo_5.0-1_208-240_firmware
  • symo_advanced_15.0-3_480_firmware
  • primo_10.0-1_208-240
  • symo_advanced_12.0-3_208-240
  • primo_5.0-1_sc_firmware
  • symo_4.5-3-s_firmware
  • primo_8.2-1_firmware
  • galvo_3.0-1
  • primo_3.8-1_208-240
  • primo_15.0-1_208-240_firmware
  • primo_12.5-1_208-240
  • galvo_2.5-1_208-240
  • galvo_2.0-1_208-240_firmware
  • symo_advanced_15.0-3_480
  • primo_6.0-1_208-240_firmware
  • symo_3.0-3-s
  • primo_3.5-1_firmware
  • symo_advanced_22.7-3_480_firmware
  • primo_3.6-1
  • primo_11.4-1_208-240_firmware
  • symo_10.0-3_208-240_firmware
  • symo_4.5-3-m_firmware
  • symo_hybrid_5.0-3-m_firmware
  • primo_10.0-1_208-240_firmware
  • symo_10.0-3_208-240
  • symo_10.0-3_480
  • primo_3.8-1_208-240_firmware
  • primo_7.6-1_208-240
  • primo_5.0-1_208-240
  • galvo_2.5-1_firmware
  • symo_17.5-3_480
  • symo_hybrid_5.0-3-m
  • primo_4.6-1
  • primo_6.0-1_208-240
  • symo_5.0-3-m_firmware
  • galvo_1.5-1_firmware
  • primo_5.0-1_aus_firmware
  • primo_5.0-1
  • eco_27.0-3-s
  • primo_4.6-1_firmware
  • symo_24.0-3_480_firmware
  • symo_3.7-3-s
  • symo_12.5-3_480_firmware
  • symo_12.5-3-m
  • symo_3.0-3-s_firmware
  • symo_advanced_10.0-3_208-240_firmware
  • galvo_3.0-1_firmware
  • symo_15.0-3-m
  • primo_12.5-1_208-240_firmware
  • primo_4.0-1
  • primo_3.6-1_firmware
  • eco_27.0-3-s_firmware
  • symo_22.7-3_480_firmware
  • symo_4.5-3-m
  • galvo_2.0-1
  • eco_25.0-3-s_firmware
  • primo_3.5-1
  • galvo_2.0-1_firmware
  • galvo_3.1-1_208-240_firmware
  • galvo_2.5-1
  • symo_15.0-3-m_firmware
  • eco_25.0-3-s
  • symo_17.5-3_480_firmware
  • symo_3.0-3-m_firmware
  • symo_10.0-3-m-os
  • symo_hybrid_3.0-3-m_firmware
  • primo_8.2-1_208-240
  • symo_17.5-3-m_firmware
  • symo_24.0-3_480
  • symo_6.0-3-m_firmware
  • primo_3.0-1
  • primo_5.0-1_firmware
  • symo_advanced_20.0-3_480
  • symo_7.0-3-m
  • primo_8.2-1_208-240_firmware
  • primo_6.0-1_firmware
  • symo_advanced_20.0-3_480_firmware
  • symo_hybrid_3.0-3-m
  • symo_7.0-3-m_firmware
  • galvo_3.1-1
  • symo_4.5-3-s
  • symo_12.5-3-m_firmware
  • symo_8.2-3-m_firmware
  • galvo_1.5-1
  • primo_5.0-1_aus
  • primo_15.0-1_208-240
  • symo_hybrid_4.0-3-m_firmware
  • galvo_1.5-1_208-240_firmware
  • symo_20.0-3_480
  • primo_6.0-1
  • symo_3.7-3-m_firmware
  • primo_5.0-1_sc
  • symo_10.0-3-m_firmware
  • symo_15.0-3_480_firmware
  • primo_3.0-1_firmware
  • symo_17.5-3-m
  • galvo_3.1-1_208-240
  • symo_12.0-3_208-240_firmware
  • primo_7.6-1_208-240_firmware
  • datamanager_box_2.0
  • symo_15.0-3_107_firmware
  • galvo_2.0-1_208-240
  • datamanager_box_2.0_firmware
  • primo_4.0-1_firmware
  • primo_8.2-1
  • symo_20.0-3-m
  • symo_advanced_12.0-3_208-240_firmware
  • primo_11.4-1_208-240
  • symo_advanced_22.7-3_480
  • symo_20.0-3-m_firmware
  • symo_10.0-3-m
  • symo_hybrid_4.0-3-m
  • symo_15.0-3_480
  • symo_6.0-3-m
  • galvo_1.5-1_208-240
  • symo_20.0-3_480_firmware
  • symo_3.0-3-m
  • symo_10.0-3-m-os_firmware
  • symo_3.7-3-m
  • symo_5.0-3-m
  • symo_advanced_10.0-3_208-240
  • galvo_3.1-1_firmware
  • symo_10.0-3_480_firmware
  • symo_22.7-3_480
  • symo_12.0-3_208-240
  • symo_3.7-3-s_firmware
  • symo_advanced_24.0-3_480
  • symo_8.2-3-m
  • galvo_2.5-1_208-240_firmware
  • symo_advanced_24.0-3_480_firmware
  • symo_12.5-3_480
  • symo_15.0-3_107
CWE
CWE-312

Cleartext Storage of Sensitive Information