CVE-2019-11367

CRITICAL

AUO Solar Data Recorder <1.3.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in AUO Solar Data Recorder before 1.3.0. The web portal uses HTTP Basic Authentication and provides the account and password in the WWW-Authenticate attribute. By using this account and password, anyone can login successfully.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0282
EPSS Percentile 85.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-311 CWE-522
Status published
Products (1)
auo/solar_data_recorder < 1.3.0
Published Jun 03, 2019
Tracked Since Feb 18, 2026