CVE-2023-29919: Critical severity solarview compact vulnerability
Published May 23, 2023
·Updated
SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.
Affected Software
4 affected components
Contec Solarview Compact Firmware<=6.0
Contec SolarView Compact
All of the following
Contec Solarview Compact Firmware<=6.0
Contec SolarView Compact
Event History
May 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-29919?
CVE-2023-29919 is a vulnerability in SolarView Compact firmware version 6.0 and below that allows any file on the server to be read or modified due to insecure permissions.
2
How severe is CVE-2023-29919?
CVE-2023-29919 has a severity value of 9.1, which is considered critical.
3
Which software versions are affected by CVE-2023-29919?
The SolarView Compact firmware versions up to and including 6.0 are affected by CVE-2023-29919.
4
What is the Common Weakness Enumeration (CWE) identifier for CVE-2023-29919?
The CWE identifier for CVE-2023-29919 is 276.
5
How can I fix CVE-2023-29919?
To fix CVE-2023-29919, it is recommended to upgrade the SolarView Compact firmware to a version that addresses the insecure permissions vulnerability.