Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-21878 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) all… Iq Gateway Firmware 8.2.4225+ Fix from $2,3002024-08-12 HIGH 8.8 CVE-2024-21879 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoin… Iq Gateway Firmware 8.2.4225+ Fix from $1,9502024-08-12 HIGH 7.2 CVE-2024-21880 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint i… Iq Gateway Firmware after 7.3.120 Fix from $1,9502024-08-12 CRITICAL 9.1 CVE-2024-21876 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly know… Iq Gateway Firmware 8.2.4225+ Fix from $2,3002024-08-12 MEDIUM 6.5 CVE-2024-21877 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly … Iq Gateway Firmware 8.2.4225+ Fix from $1,6002024-08-12 CRITICAL 9.8 CVE-2023-33869 Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands. Envoy Firmware Mitigation only Fix from $2,3002023-06-20 HIGH 7.5 CVE-2023-32274 Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this… Installer Toolkit Mitigation only Fix from $1,9502023-06-20 HIGH 8.8 CVE-2020-25755 An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows rem… Envoy Firmware No fix yet Fix from $1,9502021-06-16 HIGH 7.5 CVE-2020-25754 An issue was discovered on Enphase Envoy R3.x and D4.x devices. There is a custom PAM module for user authentication that circumvents traditional use… Envoy Firmware No fix yet Fix from $1,9502021-06-16 CRITICAL 9.8 CVE-2020-25753 An issue was discovered on Enphase Envoy R3.x and D4.x devices with v3 software. The default admin password is set to the last 6 digits of the serial… Envoy Firmware No fix yet Fix from $2,3002021-06-16 MEDIUM 5.3 CVE-2020-25752 An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts.… Envoy Firmware No fix yet Fix from $1,6002021-06-16 CRITICAL 9.8 CVE-2019-7678 A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888. Envoy after 3.9.0 Fix from $2,3002019-02-09 HIGH 7.2 CVE-2019-7676 A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account. Envoy after 3.9.0 Fix from $1,9502019-02-09 MEDIUM 6.1 CVE-2019-7677 XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888. Envoy after 3.9.0 Fix from $1,6002019-02-09