CVE-2020-9306: High severity tesla solarcity solar monitoring gateway vulnerability
Tesla SolarCity Solar Monitoring Gateway through 5.46.43 has a "Use of Hard-coded Credentials" issue because Digi ConnectPort X2e uses a .pyc file to store the cleartext password for the python user account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-9306?
CVE-2020-9306 is classified as a medium-severity vulnerability due to the risk posed by hard-coded credentials.
How do I fix CVE-2020-9306?
To mitigate CVE-2020-9306, remove the hard-coded credentials from the .pyc file and implement secure credential storage practices.
What software versions are affected by CVE-2020-9306?
CVE-2020-9306 affects Tesla SolarCity Solar Monitoring Gateway versions up to and including 5.46.43.
What causes CVE-2020-9306?
CVE-2020-9306 is caused by the use of hard-coded credentials stored in a .pyc file for the python user account.
Can CVE-2020-9306 lead to unauthorized access?
Yes, CVE-2020-9306 can lead to unauthorized access because the cleartext password is easily accessible.