Vulnerability Description
An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Unpro
- https://www.solar-log.com/en/support/firmware-database-1
- https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Unpro
FAQ
What is CVE-2024-40116?
CVE-2024-40116 is a vulnerability with a CVSS score of 8.1 (HIGH). An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL...
How severe is CVE-2024-40116?
CVE-2024-40116 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40116?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.