CVE-2024-21877
CVE-2024-21877 is a path traversal vulnerability in Enphase IQ Gateway (formerly Envoy), potentially allowing unauthorized file manipulation. An attacker could exploit this vulnerability by manipulating the URL parameter, enabling them to access files and directories outside the intended restricted area. Although the CVSS score is 0, indicating no immediate risk based solely on that metric, the SOCRadar Vulnerability Risk Score (SVRS) of 61 suggests a moderate level of concern. This vulnerability requires authentication, but successful exploitation could lead to data breaches or system compromise. Enphase IQ Gateway versions 4.x through 8.0 and versions prior to 8.2.4225 are affected. The risk is significant because it could lead to unauthorized access to sensitive data and potentially allow for remote code execution if combined with other vulnerabilities. Therefore, patching to version 8.2.4225 or later is strongly recommended to mitigate the security risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.