Vulnerabilities > Fronius > Symo 22 7 3 480 Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-12-04 CVE-2019-19229 Path Traversal vulnerability in Fronius products
admincgi-bin/service.fcgi on Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allows action=download&filename= Directory Traversal.
network
low complexity
fronius CWE-22
4.0
2019-12-04 CVE-2019-19228 Cleartext Storage of Sensitive Information vulnerability in Fronius products
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
network
low complexity
fronius CWE-312
5.0