CVE-2024-21879: URL parameter manipulations allows an authenticated attacker to execute arbitrary OS commands in Enphase IQ Gateway v4.x to v8.x and < v8.2.4225
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21879?
CVE-2024-21879 is rated as a high-severity vulnerability due to its potential for OS command injection.
How do I fix CVE-2024-21879?
To mitigate CVE-2024-21879, upgrade the Enphase IQ Gateway firmware to version 8.2.4225 or later.
Which versions of the software are affected by CVE-2024-21879?
CVE-2024-21879 affects Enphase IQ Gateway firmware versions from 4.x to below 8.2.4225.
What type of vulnerability is CVE-2024-21879?
CVE-2024-21879 is classified as a command injection vulnerability arising from improper neutralization of special elements.
What impact does CVE-2024-21879 have on affected systems?
CVE-2024-21879 could allow an attacker to execute arbitrary operating system commands on the affected Enphase IQ Gateway.