Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-19492 | Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x |
Solution
Devices are remotely being updated by the vendor.
Workaround
It is adviced to not expose this device to untrusted network acces. In other words, make sure this decvice is not reachable from the internet, a guest network or a public network.
Mon, 12 Aug 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Enphase
Enphase envoy |
|
| CPEs | cpe:2.3:h:enphase:envoy:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Enphase
Enphase envoy |
|
| Metrics |
ssvc
|
Sat, 10 Aug 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x | |
| Title | Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x | |
| Weaknesses | CWE-326 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: DIVD
Published:
Updated: 2025-03-11T13:38:24.981Z
Reserved: 2024-01-02T18:30:11.175Z
Link: CVE-2024-21881
Updated: 2024-08-12T16:37:18.414Z
Status : Awaiting Analysis
Published: 2024-08-12T13:38:15.500
Modified: 2024-08-12T13:41:36.517
Link: CVE-2024-21881
No data.
OpenCVE Enrichment
No data.
EUVD