Enphase Installer Toolkit Android App Use of Hard-coded Credentials
CVE-2023-32274

8.6HIGH

Key Information:

Vendor

Enphase

Vendor
CVE Published:
20 June 2023

What is CVE-2023-32274?

The Enphase Installer Toolkit app, specifically version 3.27.0, contains hard coded credentials within its binary code. This security flaw can be exploited by attackers, allowing them unauthorized access to sensitive information stored within the application. Users should be aware of potential risks associated with this vulnerability to protect their data.

Affected Version(s)

Enphase Installer Toolkit 3.27.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OBSWCY3F reported this vulnerability to CISA.
.