CVE-2024-40116

An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.
Configurations

No configuration.

History

26 Mar 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Unprotected%20Storage%20of%20Credentials - () https://github.com/nepenthe0320/cve_poc/blob/master/Solar-Log%201000%20-%20Unprotected%20Storage%20of%20Credentials -

11 Nov 2024, 23:15

Type Values Removed Values Added
References
  • () https://www.solar-log.com/en/support/firmware-database-1 -
Summary (en) An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files. (en) An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.2013 was discovered to store plaintext passwords in the export.html, email.html, and sms.html files -- fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

01 Aug 2024, 13:56

Type Values Removed Values Added
CWE CWE-256

29 Jul 2024, 14:12

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en Solar-Log 1000 anterior a v2.8.2 y compilación 52-23.04.2013 al almacenar contraseñas en texto plano en los archivos export.html, email.html y sms.html.

26 Jul 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-26 20:15

Updated : 2025-03-26 16:15


NVD link : CVE-2024-40116

Mitre link : CVE-2024-40116

CVE.ORG link : CVE-2024-40116


JSON object : View

Products Affected

No product.

CWE
CWE-256

Plaintext Storage of a Password