Vulnerabilities (CVE)

Filtered by vendor Fronius Subscribe
Filtered by product Datamanager Box 2.0
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-19229 1 Fronius 132 Datamanager Box 2.0, Datamanager Box 2.0 Firmware, Eco 25.0-3-s and 129 more 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
CVE-2019-19228 1 Fronius 132 Datamanager Box 2.0, Datamanager Box 2.0 Firmware, Eco 25.0-3-s and 129 more 2024-11-21 5.0 MEDIUM 9.8 CRITICAL
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.