The management web pages on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware prior to 2.0.2870_2.2.12 do not require authentication, which allows remote malicious users to obtain administrative access via a direct request, as demonstrated by a request to ping.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sinapsitech sinapsi_firmware |
||
sinapsitech esolar_photovoltaic_system_monitor - |
||
sinapsitech esolar_light_photovoltaic_system_monitor - |
||
sinapsitech esolar_duo_photovoltaic_system_monitor - |