CVE-2012-5862
Sinapsi eSolar, eSolar DUO, eSolar Light and sinapsi_firmware < 2.0.2870 - Use of Hard-coded Password
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5862. PoCs published by Roberto Paleari.
AI-analyzed exploit summary This advisory details multiple vulnerabilities in the Schneider Electric Ezylog photovoltaic SCADA management server, including SQL injection, hard-coded accounts, command injection, and broken session enforcement. It provides technical analysis, code snippets, and exploitation examples.
Description
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access.
Exploits (1)
This advisory details multiple vulnerabilities in the Schneider Electric Ezylog photovoltaic SCADA management server, including SQL injection, hard-coded accounts, command injection, and broken session enforcement. It provides technical analysis, code snippets, and exploitation examples.