CVE-2023-32274: Enphase Installer Toolkit Android App Use of Hard-coded Credentials
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32274?
CVE-2023-32274 is rated as a critical vulnerability due to the presence of hard coded credentials in the Enphase Installer Toolkit Android application.
How do I fix CVE-2023-32274?
To remediate CVE-2023-32274, update the Enphase Installer Toolkit to a version that does not include hard coded credentials.
What is affected by CVE-2023-32274?
CVE-2023-32274 affects Enphase Installer Toolkit version 3.27.0 specifically.
What could an attacker gain by exploiting CVE-2023-32274?
An attacker could gain unauthorized access to sensitive information by exploiting the hard coded credentials in CVE-2023-32274.
Are earlier versions of Enphase Installer Toolkit affected by CVE-2023-32274?
Only version 3.27.0 of the Enphase Installer Toolkit is specifically identified as vulnerable in CVE-2023-32274.