Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-23-171-02 Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2023-06-20T19:38:42.467Z

Updated: 2023-06-20T19:38:42.467Z

Reserved: 2023-05-25T19:20:22.591Z


Link: CVE-2023-32274

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-06-20T20:15:09.413

Modified: 2023-06-28T01:47:20.540


Link: CVE-2023-32274

JSON object: View

cve-icon Redhat Information

No data.

CWE