CVE-2020-9306
HIGHTesla Solarcity Solar Monitoring Gateway < 5.46.43 - Insufficiently Protected Credentials
Title source: ruleDescription
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
Scores
CVSS v3
8.8
EPSS
0.0022
EPSS Percentile
44.6%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-522
CWE-798
Status
published
Affected Products (1)
tesla/solarcity_solar_monitoring_gateway
< 5.46.43
Timeline
Published
Feb 18, 2021
Tracked Since
Feb 18, 2026