2025-03-02 03:03:52 +00:00

60 lines
2.0 KiB
JSON

{
"id": "CVE-2024-8893",
"sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"published": "2025-02-14T17:15:18.690",
"lastModified": "2025-02-14T17:15:18.690",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500\u2011XS allows anyone in physical proximity to the device to fully access the web interface of the inverter via Wi\u2011Fi.This issue affects GW1500\u2011XS: 1.1.2.1."
},
{
"lang": "es",
"value": "La vulnerabilidad de uso de credenciales codificadas en GoodWe Technologies Co., Ltd. GW1500-XS permite que cualquier persona que se encuentre f\u00edsicamente cerca del dispositivo acceda completamente a la interfaz web del inversor a trav\u00e9s de Wi-Fi. Este problema afecta a GW1500-XS: 1.1.2.1."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
"baseScore": 7.3,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 3.9,
"impactScore": 3.4
}
]
},
"weaknesses": [
{
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-798"
}
]
}
],
"references": [
{
"url": "https://os-s.net/publications/advisories/CVE-2024-8893.pdf",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}
]
}