Show filters
94 Total Results
Displaying 91-94 of 94
Sort by:
Attacker Value
Unknown
CVE-2019-9900
Disclosure Date: April 25, 2019 (last updated November 08, 2023)
When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources.
0
Attacker Value
Unknown
CVE-2019-7676
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
A weak password vulnerability was discovered in Enphase Envoy R3.*.*. One can login via TCP port 8888 with the admin password for the admin account.
0
Attacker Value
Unknown
CVE-2019-7678
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
A directory traversal vulnerability was discovered in Enphase Envoy R3.*.* via images/, include/, include/js, or include/css on TCP port 8888.
0
Attacker Value
Unknown
CVE-2019-7677
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
XSS exists in Enphase Envoy R3.*.* via the profileName parameter to the /home URI on TCP port 8888.
0