Enphase IQ Gateway Vulnerable to Command Injection through URL Parameter
CVE-2024-21879

8.7HIGH

Key Information:

Vendor

Enphase

Status
Vendor
CVE Published:
12 August 2024

What is CVE-2024-21879?

A vulnerability exists within the Enphase IQ Gateway, previously branded as Envoy, that allows for the improper handling of special elements used in command execution, specifically through a URL parameter in an authenticated endpoint. This flaw exposes the system to potential OS command injection attacks, enabling unauthorized execution of arbitrary commands on affected systems. The versions at risk range from 4.x to 8.x, specifically those below 8.2.4225. This issue necessitates immediate attention for users of this product to safeguard against potential exploitation.

Affected Version(s)

Envoy 8.x < 8.2.4225

Envoy 7.x

Envoy 6.x

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wietse Boonstra of DIVD
Hidde Smit of DIVD
Frank Breedijk of DIVD
Max van der Horst of DIVD
.