CVE-2012-6428

Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 establishes multiple hardcoded accounts, which makes it easier for remote attackers to obtain administrative access by reading a password in a PHP script, a similar issue to CVE-2012-5862.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
icscertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
carlosgavazzieos-box_photovoltaic_monitoring_system_firmware
𝑥
≤ 1.0.0
carlosgavazzieos-box_photovoltaic_monitoring_system
-
𝑥
= Vulnerable software versions
Common Weakness Enumeration