Release date:
Updated on:
Affected Systems:
Sinapsi eSolar 2.x
Sinapsi eSolar DUO 2.x
Sinapsi eSolar Light 2.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-5863
Sinapsi eSolar Light is a monitoring system used in solar applications.
ESolar, eSolar DUO, and eSolar Light do not check the specific elements sent to the system command. Attackers can execute arbitrary operating system commands by using administrator privileges to access some pages without verification.
<* Source: vendor
Link: http://secunia.com/advisories/51364/
Http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Sinapsi
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sinapsitech.it/