Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36528 | Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information. |
Fixes
Solution
No solution given by the vendor.
Workaround
Users of the affected product are encouraged to contact Enphase Energy support https://support.enphase.com/s/contact-us for additional information.
References
History
Fri, 06 Dec 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-12-06T21:34:38.813Z
Reserved: 2023-05-25T19:20:22.591Z
Link: CVE-2023-32274
Updated: 2024-08-02T15:10:24.324Z
Status : Modified
Published: 2023-06-20T20:15:09.413
Modified: 2024-11-21T08:03:01.410
Link: CVE-2023-32274
No data.
OpenCVE Enrichment
No data.
EUVD