Envoy
Enphase · 9 CVEs
Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225
Aug 10, 2024
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.…
Aug 10, 2024
Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225
Aug 10, 2024
Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x
Aug 10, 2024
URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway ver…
Aug 10, 2024
Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x
Aug 10, 2024
Enphase Envoy OS Command Injection
Jun 20, 2023
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or includ…
Feb 9, 2019
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
Feb 9, 2019
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin pa…
Feb 9, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-21876 | Unauthenticated Path Traversal via URL Parameter in Enphase IQ Gateway version < 8.2.4225 | CRITICAL | 0.80% | Aug 10, 2024 |
| CVE-2024-21879 | URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225 | HIGH | 2.50% | Aug 10, 2024 |
| CVE-2024-21877 | Insecure File Generation Based on User Input in Enphase IQ Gateway version 4.x to 8.x and < 8.2.4225 | CRITICAL | 0.79% | Aug 10, 2024 |
| CVE-2024-21878 | Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x | CRITICAL | 1.44% | Aug 10, 2024 |
| CVE-2024-21880 | URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway version 4.x <= 7.x | HIGH | 2.35% | Aug 10, 2024 |
| CVE-2024-21881 | Upload of encrypted packages allows authenticated command execution in Enphase IQ Gateway v4.x and v5.x | HIGH | 0.29% | Aug 10, 2024 |
| CVE-2023-33869 | Enphase Envoy OS Command Injection | CRITICAL | 1.11% | Jun 20, 2023 |
| CVE-2019-7678 | A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888. | CRITICAL | 2.49% | Feb 9, 2019 |
| CVE-2019-7677 | XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888. | MEDIUM | 0.90% | Feb 9, 2019 |
| CVE-2019-7676 | A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account. | HIGH | 1.69% | Feb 9, 2019 |
Showing 1 to 9 of 9 CVEs