10
CVSSv2

CVE-2012-5862

Published: 23/11/2012 Updated: 29/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

login.php on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware prior to 2.0.2870_2.2.12 establishes multiple hardcoded accounts, which makes it easier for remote malicious users to obtain administrative access by leveraging a (1) cleartext password or (2) password hash contained in this script, as demonstrated by a password of astridservice or 36e44c9b64.

Vulnerable Product Search on Vulmon Subscribe to Product

sinapsitech sinapsi_firmware

sinapsitech esolar_photovoltaic_system_monitor -

sinapsitech esolar_light_photovoltaic_system_monitor -

sinapsitech esolar_duo_photovoltaic_system_monitor -

Exploits

Multiple vulnerabilities in Ezylog photovoltaic management server ================================================================= [ADVISORY INFORMATION] Title: Multiple vulnerabilities in Ezylog photovoltaic management server Discovery date: 27/08/2012 Release date: 11/09/2012 Credits: Roberto Paleari (roberto@greyhatsit, @rpa ...