CVE-2024-21878: Command Injection through Unsafe File Name Evaluation in internal script in Enphase IQ Gateway v4.x to and including 8.x
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21878?
CVE-2024-21878 is classified as a critical severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2024-21878?
To mitigate CVE-2024-21878, it is recommended to update the Enphase IQ Gateway firmware to a version later than 8.2.4225.
Which versions of Enphase IQ Gateway are affected by CVE-2024-21878?
CVE-2024-21878 affects Enphase IQ Gateway firmware versions from 4.x up to and including 8.2.4225.
What kind of attack can exploit CVE-2024-21878?
CVE-2024-21878 can be exploited for command injection attacks, enabling an attacker to execute arbitrary commands on the vulnerable system.
Is Enphase IQ Gateway hardware affected by CVE-2024-21878?
CVE-2024-21878 specifically affects the firmware of the Enphase IQ Gateway and not the hardware itself.