Enphase IQ Gateway Vulnerable to Command Injection via Internal Script
CVE-2024-21878
9.2CRITICAL
What is CVE-2024-21878?
A command injection vulnerability exists in Enphase IQ Gateway (formerly known as Envoy) due to improper neutralization of special elements in a command. This flaw allows attackers to execute operating system commands by exploiting an internal script, leading to potential unauthorized access and manipulation of the affected system. The vulnerability impacts versions 4.x through 8.x of the Envoy, and as of now, there is no patch available to mitigate this serious security risk. Organizations utilizing these affected versions should prioritize addressing this issue to safeguard their networks and data against potential exploitation.
Affected Version(s)
Envoy 8.x
Envoy 8.x < 8.2.4225
Envoy 7.x
References
CVSS V4
Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Wietse Boonstra of DIVD
Hidde Smit of DIVD
Frank Breedijk of DIVD
Max van der Horst of DIVD
