First published: Sat Aug 10 2024(Updated: )
Inadequate Encryption Strength vulnerability allow an authenticated attacker to execute arbitrary OS Commands via encrypted package upload.This issue affects Envoy: 4.x and 5.x
Credit: csirt@divd.nl
Affected Software | Affected Version | How to fix |
---|---|---|
Envoy Proxy | >=4.x<=5.x | |
Enphase IQ Gateway Firmware | >=4.x<=5.x |
Devices are remotely being updated by the vendor.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21881 is classified as a medium severity vulnerability.
To fix CVE-2024-21881, update Envoy and Enphase IQ Gateway to the latest version available.
An authenticated attacker can exploit CVE-2024-21881 to execute arbitrary OS commands.
CVE-2024-21881 affects Envoy and Enphase IQ Gateway versions from 4.x to 5.x.
CVE-2024-21881 is an Inadequate Encryption Strength vulnerability.