Enphase IQ Gateway Vulnerable to Command Injection via Internal Script
CVE-2024-21878

9.2CRITICAL

Key Information:

Vendor

Enphase

Status
Vendor
CVE Published:
12 August 2024

What is CVE-2024-21878?

A command injection vulnerability exists in Enphase IQ Gateway (formerly known as Envoy) due to improper neutralization of special elements in a command. This flaw allows attackers to execute operating system commands by exploiting an internal script, leading to potential unauthorized access and manipulation of the affected system. The vulnerability impacts versions 4.x through 8.x of the Envoy, and as of now, there is no patch available to mitigate this serious security risk. Organizations utilizing these affected versions should prioritize addressing this issue to safeguard their networks and data against potential exploitation.

Affected Version(s)

Envoy 8.x

Envoy 8.x < 8.2.4225

Envoy 7.x

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wietse Boonstra of DIVD
Hidde Smit of DIVD
Frank Breedijk of DIVD
Max van der Horst of DIVD
.