Back to search
CVE-2012-5864
Published: Nov 23, 2012
Modified: Jul 8, 2025
PUBLISHED
Description
These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.
| Vendor | Product | Versions |
|---|---|---|
Sinapsi | eSolar | affected 0 - < 2.0.2870_xxx_2.2.12 |
Sinapsi | eSolar DUO | affected 0 - < 2.0.2870_xxx_2.2.12 |
Sinapsi | eSolar Light | affected 0 - < 2.0.2870_xxx_2.2.12 |
Weaknesses (CWE)
References
21273
exploit
x_refsource_EXPLOIT-DB
20120911 Multiple vulnerabilities in Ezylog photovoltaic management server
mailing-list
x_refsource_BUGTRAQ
sinapsi-default-password(80200)
vdb-entry
x_refsource_XF
http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now