Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.
History

Fri, 23 Aug 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Enphase iq Gateway
Enphase iq Gateway Firmware
Weaknesses CWE-78
CPEs cpe:2.3:h:enphase:iq_gateway:-:*:*:*:*:*:*:*
cpe:2.3:o:enphase:iq_gateway_firmware:*:*:*:*:*:*:*:*
Vendors & Products Enphase iq Gateway
Enphase iq Gateway Firmware
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 12 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Enphase
Enphase envoy
CPEs cpe:2.3:h:enphase:envoy:*:*:*:*:*:*:*:*
Vendors & Products Enphase
Enphase envoy
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 10 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.
Title Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x
Weaknesses CWE-77
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/S:P/AU:Y/R:I/V:C/RE:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: DIVD

Published: 2024-08-10T17:44:48.892Z

Updated: 2024-08-12T14:30:47.907Z

Reserved: 2024-01-02T18:30:11.174Z

Link: CVE-2024-21878

cve-icon Vulnrichment

Updated: 2024-08-12T14:30:39.302Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T13:38:15.107

Modified: 2024-08-23T17:52:11.777

Link: CVE-2024-21878

cve-icon Redhat

No data.