CVE Database
/

CVE-2024-21881

Back to search

CVE-2024-21881

Published: Aug 10, 2024

Modified: Mar 11, 2025

PUBLISHED

Description

Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x

VendorProductVersions

Enphase

Envoy

affected
5.x
affected
4.x

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now