CVE-2012-5863
By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 24.82% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78, CWE-264
- Affected
- sinapsitech/sinapsi firmware · sinapsitech/esolar duo photovoltaic system monitor · sinapsitech/esolar light photovoltaic system monitor · sinapsitech/esolar photovoltaic system monitor
- Source
- ics-cert@hq.dhs.gov
References
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.htmlExploit
- http://www.exploit-db.com/exploits/21273/Exploit
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80200
- https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.htmlExploit
- http://www.exploit-db.com/exploits/21273/Exploit
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdfUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80202
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.