ID

VAR-201506-0354


CVE

CVE-2015-3949


TITLE

Sinapsi eSolar Light Vulnerability in obtaining plaintext password in firmware

Trust: 0.8

sources: JVNDB: JVNDB-2015-003088

DESCRIPTION

Sinapsi eSolar Light with firmware before 2.0.3970_schsl_2.2.85 allows attackers to discover cleartext passwords by reading the HTML source code of the mail-configuration page. Sinapsi eSolar Light is prone to a local information-disclosure vulnerability. Local attackers can exploit this issue to obtain sensitive information such as saved passwords that may aid in launching further attacks. Sinapsi eSolar Light is a monitoring system for use in solar applications by the Italian company Sinapsi. A security vulnerability exists in the Sinapsi eSolar Light with firmware versions prior to 2.0.3970_schsl_2.2.85

Trust: 1.98

sources: NVD: CVE-2015-3949 // JVNDB: JVNDB-2015-003088 // BID: 75100 // VULHUB: VHN-81910

AFFECTED PRODUCTS

vendor:sinapsimodel:esolar lightscope:lteversion:2.0.3970

Trust: 1.0

vendor:sinapsimodel:esolar lightscope: - version: -

Trust: 0.8

vendor:sinapsimodel:esolar lightscope:ltversion:2.0.3970_schsl_2.2.85

Trust: 0.8

vendor:sinapsimodel:esolar lightscope:eqversion:2.0.3970

Trust: 0.6

vendor:sinapsimodel:esolar light 2.0.3970 schsl 2.2.8scope: - version: -

Trust: 0.3

sources: BID: 75100 // JVNDB: JVNDB-2015-003088 // CNNVD: CNNVD-201506-262 // NVD: CVE-2015-3949

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-3949
value: LOW

Trust: 1.0

NVD: CVE-2015-3949
value: LOW

Trust: 0.8

CNNVD: CNNVD-201506-262
value: LOW

Trust: 0.6

VULHUB: VHN-81910
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2015-3949
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-81910
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-81910 // JVNDB: JVNDB-2015-003088 // CNNVD: CNNVD-201506-262 // NVD: CVE-2015-3949

PROBLEMTYPE DATA

problemtype:CWE-200

Trust: 1.9

sources: VULHUB: VHN-81910 // JVNDB: JVNDB-2015-003088 // NVD: CVE-2015-3949

THREAT TYPE

local

Trust: 0.9

sources: BID: 75100 // CNNVD: CNNVD-201506-262

TYPE

information disclosure

Trust: 0.6

sources: CNNVD: CNNVD-201506-262

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-003088

PATCH

title:Sinapsi eSolar Lighturl:http://www.sinapsitech.it/en/wpcproduct/esolar-light/

Trust: 0.8

sources: JVNDB: JVNDB-2015-003088

EXTERNAL IDS

db:NVDid:CVE-2015-3949

Trust: 2.8

db:ICS CERTid:ICSA-15-160-02

Trust: 2.8

db:BIDid:75100

Trust: 1.4

db:JVNDBid:JVNDB-2015-003088

Trust: 0.8

db:CNNVDid:CNNVD-201506-262

Trust: 0.7

db:VULHUBid:VHN-81910

Trust: 0.1

sources: VULHUB: VHN-81910 // BID: 75100 // JVNDB: JVNDB-2015-003088 // CNNVD: CNNVD-201506-262 // NVD: CVE-2015-3949

REFERENCES

url:https://ics-cert.us-cert.gov/advisories/icsa-15-160-02

Trust: 2.8

url:http://www.securityfocus.com/bid/75100

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-3949

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-3949

Trust: 0.8

url:http://www.sinapsitech.it/

Trust: 0.3

sources: VULHUB: VHN-81910 // BID: 75100 // JVNDB: JVNDB-2015-003088 // CNNVD: CNNVD-201506-262 // NVD: CVE-2015-3949

CREDITS

Maxim Rupp

Trust: 0.3

sources: BID: 75100

SOURCES

db:VULHUBid:VHN-81910
db:BIDid:75100
db:JVNDBid:JVNDB-2015-003088
db:CNNVDid:CNNVD-201506-262
db:NVDid:CVE-2015-3949

LAST UPDATE DATE

2025-04-13T23:23:44.666000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-81910date:2016-12-06T00:00:00
db:BIDid:75100date:2015-06-09T00:00:00
db:JVNDBid:JVNDB-2015-003088date:2015-06-16T00:00:00
db:CNNVDid:CNNVD-201506-262date:2015-06-18T00:00:00
db:NVDid:CVE-2015-3949date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-81910date:2015-06-13T00:00:00
db:BIDid:75100date:2015-06-09T00:00:00
db:JVNDBid:JVNDB-2015-003088date:2015-06-16T00:00:00
db:CNNVDid:CNNVD-201506-262date:2015-06-15T00:00:00
db:NVDid:CVE-2015-3949date:2015-06-13T18:59:01.277