CVE-2012-5863 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 24.8% (pctl 98)
Patch early
A public exploit exists.
Description
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 24.82% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-11-23 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| sinapsitech | esolar duo photovoltaic system monitor |
| sinapsitech | esolar light photovoltaic system monitor |
| sinapsitech | esolar photovoltaic system monitor |
| sinapsitech | sinapsi firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Ezylog Photovoltaic Management Server - Multiple Vulnerabilities | 2012-09-12 |
References
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
- http://www.exploit-db.com/exploits/21273/
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80200
- https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
- http://www.exploit-db.com/exploits/21273/
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80202
→ the Explorer · watch your stack · NVD