CVE-2020-9306
HIGHTesla Solarcity Solar Monitoring Gateway < 5.46.43 - Insufficiently Protected Credentials
Title source: ruleDescription
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
References (4)
Core 4
Core References
Third Party Advisory x_refsource_misc
https://www.fireeye.com/blog/threat-research.html
Third Party Advisory x_refsource_misc
https://www.fireeye.com/blog/threat-research/2021/02/solarcity-exploitation-of-x2e-iot-device-part-one.html
Exploit, Third Party Advisory x_refsource_misc
https://www.fireeye.com/blog/threat-research/2021/02/solarcity-exploitation-of-x2e-iot-device-part-two.html
Third Party Advisory x_refsource_confirm
https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2020-0019/FEYE-2020-0019.md
Scores
CVSS v3
8.8
EPSS
0.0022
EPSS Percentile
44.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-522
CWE-798
Status
published
Products (1)
tesla/solarcity_solar_monitoring_gateway
< 5.46.43
Published
Feb 18, 2021
Tracked Since
Feb 18, 2026