{
    "id": "CVE-2012-5861",
    "published": "2012-11-23 12:09:58",
    "last_modified": "2026-06-16 23:47:28",
    "cvss_score": "7.8",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:N/A:N",
    "cwe": "CWE-89",
    "description": "These Sinapsi devices do not check the validity of the data before \nexecuting queries. By accessing the SQL table of certain pages that do \nnot require authentication within the device, attackers can leak \ninformation from the device. This could allow the attacker to compromise\n confidentiality.",
    "epss_score": "0.04239",
    "epss_percentile": "0.90751",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-06 18:17:10",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "sinapsitech",
            "product": "esolar_duo_photovoltaic_system_monitor"
        },
        {
            "vendor": "sinapsitech",
            "product": "esolar_light_photovoltaic_system_monitor"
        },
        {
            "vendor": "sinapsitech",
            "product": "esolar_photovoltaic_system_monitor"
        },
        {
            "vendor": "sinapsitech",
            "product": "sinapsi_firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "21273",
            "title": "Ezylog Photovoltaic Management Server - Multiple Vulnerabilities",
            "date": "2012-09-12",
            "url": "https://www.exploit-db.com/exploits/21273"
        }
    ],
    "refs_list": [
        "http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html",
        "http://www.exploit-db.com/exploits/21273/",
        "http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/80200",
        "https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01",
        "http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html",
        "http://www.exploit-db.com/exploits/21273/",
        "http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88",
        "http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf",
        "https://exchange.xforce.ibmcloud.com/vulnerabilities/80201"
    ]
}