Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x
Metrics
Affected Vendors & Products
References
History
Mon, 12 Aug 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Enphase
Enphase envoy |
|
CPEs | cpe:2.3:h:enphase:envoy:-:*:*:*:*:*:*:* | |
Vendors & Products |
Enphase
Enphase envoy |
|
Metrics |
ssvc
|
Sat, 10 Aug 2024 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x | |
Title | Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x | |
Weaknesses | CWE-326 | |
References |
| |
Metrics |
cvssV4_0
|
MITRE
Status: PUBLISHED
Assigner: DIVD
Published: 2024-08-10T17:44:48.033Z
Updated: 2024-08-12T16:37:24.533Z
Reserved: 2024-01-02T18:30:11.175Z
Link: CVE-2024-21881
Vulnrichment
Updated: 2024-08-12T16:37:18.414Z
NVD
Status : Awaiting Analysis
Published: 2024-08-12T13:38:15.500
Modified: 2024-08-12T13:41:36.517
Link: CVE-2024-21881
Redhat
No data.