Exposure of Hard-Coded Credentials in SolarView Compact by Contec
CVE-2023-27512
7.2HIGH
What is CVE-2023-27512?
The SolarView Compact SV-CPT-MC310 and SV-CPT-MC310F models prior to version 8.10 are susceptible to a significant security issue stemming from hard-coded credentials. This vulnerability permits an authenticated remote attacker to gain administrative access to the device, thereby enabling them to perform unauthorized tasks, potentially compromising the system's integrity. Users are advised to upgrade to the latest firmware version to mitigate risks.
Affected Version(s)
SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
