Vulnerability Description
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fronius | Datamanager Box 2.0 Firmware | < 3.14.1 |
| Fronius | Datamanager Box 2.0 | - |
| Fronius | Eco 25.0-3-S Firmware | < 3.14.1 |
| Fronius | Eco 25.0-3-S | - |
| Fronius | Eco 27.0-3-S Firmware | < 3.14.1 |
| Fronius | Eco 27.0-3-S | - |
| Fronius | Galvo 1.5-1 Firmware | < 3.14.1 |
| Fronius | Galvo 1.5-1 | - |
| Fronius | Galvo 1.5-1 208-240 Firmware | < 3.14.1 |
| Fronius | Galvo 1.5-1 208-240 | - |
| Fronius | Galvo 2.0-1 Firmware | < 3.14.1 |
| Fronius | Galvo 2.0-1 | - |
| Fronius | Galvo 2.0-1 208-240 Firmware | < 3.14.1 |
| Fronius | Galvo 2.0-1 208-240 | - |
| Fronius | Galvo 2.5-1 Firmware | < 3.14.1 |
| Fronius | Galvo 2.5-1 | - |
| Fronius | Galvo 2.5-1 208-240 Firmware | < 3.14.1 |
| Fronius | Galvo 2.5-1 208-240 | - |
| Fronius | Galvo 3.0-1 Firmware | < 3.14.1 |
| Fronius | Galvo 3.0-1 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-InsecuExploitThird Party AdvisoryVDB Entry
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-soExploitThird Party Advisory
- https://seclists.org/bugtraq/2019/Dec/5ExploitMailing ListThird Party Advisory
- http://packetstormsecurity.com/files/155562/Fronius-Solar-Inverter-Series-InsecuExploitThird Party AdvisoryVDB Entry
- https://sec-consult.com/en/blog/advisories/multiple-vulnerabilites-in-fronius-soExploitThird Party Advisory
- https://seclists.org/bugtraq/2019/Dec/5ExploitMailing ListThird Party Advisory
FAQ
What is CVE-2019-19228?
CVE-2019-19228 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
How severe is CVE-2019-19228?
CVE-2019-19228 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-19228?
Check the references section above for vendor advisories and patch information. Affected products include: Fronius Datamanager Box 2.0 Firmware, Fronius Datamanager Box 2.0, Fronius Eco 25.0-3-S Firmware, Fronius Eco 25.0-3-S, Fronius Eco 27.0-3-S Firmware.