CVE-2023-32274: Enphase Installer Toolkit Android App Use of Hard-coded Credentials

8.6 CVSS

Description

Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.

Classification

CVE ID: CVE-2023-32274

CVSS Base Severity: HIGH

CVSS Base Score: 8.6

Affected Products

Vendor: Enphase

Product: Enphase Installer Toolkit

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.1% (probability of being exploited)

EPSS Percentile: 42.89% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.cisa.gov/news-events/ics-advisories/icsa-23-171-02

Timeline