CVE-2012-5863
Estado: ModificadaAlta (10)—
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 25%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- CWE-78
- CWE-264
Referencias
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
- http://www.exploit-db.com/exploits/21273/
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80200
- https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
- http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html
- http://www.exploit-db.com/exploits/21273/
- http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/80202
JSON original (NVD)
Mostrar
{
"id": "CVE-2012-5863",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "ics-cert@hq.dhs.gov",
"affectedData": [
{
"vendor": "Sinapsi",
"product": "eSolar",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.0.2870_xxx_2.2.12",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Sinapsi",
"product": "eSolar DUO",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.0.2870_xxx_2.2.12",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "Sinapsi",
"product": "eSolar Light",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.0.2870_xxx_2.2.12",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2012-11-23T12:09:58.477",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html",
"tags": [
"Exploit"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.exploit-db.com/exploits/21273/",
"tags": [
"Exploit"
],
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80200",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01",
"source": "ics-cert@hq.dhs.gov"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/21273/",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/80202",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "ics-cert@hq.dhs.gov",
"description": [
{
"lang": "en",
"value": "CWE-78"
}
]
},
{
"type": "Secondary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "These Sinapsi devices do not check for special elements in commands sent \nto the system. By accessing certain pages with administrative privileges\n that do not require authentication within the device, attackers can \nexecute arbitrary, unexpected, or dangerous commands directly onto the \noperating system."
},
{
"lang": "es",
"value": "ping.php en el Sinapsi eSolar Light Photovoltaic System Monitor (también conocido como servidor de gestión Schneider Electric Ezylog photovoltaic SCADA), Sinapsi eSolar, y Sinapsi eSolar DUO con firmware anterior a v2.0.2870_2.2.12 permite a atacantes remotos ejecutar comandos arbitarios mediante una shell de metacaracteres en el parámetro ip_dominio."
}
],
"lastModified": "2026-06-16T23:47:28.923",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sinapsitech:sinapsi_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "382C527D-16D4-4557-8E68-C4430416DB57",
"versionEndIncluding": "2.0.2870"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sinapsitech:esolar_duo_photovoltaic_system_monitor:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF238DD2-D119-4652-B63B-9321DFB01A90"
},
{
"criteria": "cpe:2.3:h:sinapsitech:esolar_light_photovoltaic_system_monitor:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C00B699F-DE3B-4371-B814-DE54038C60A0"
},
{
"criteria": "cpe:2.3:h:sinapsitech:esolar_photovoltaic_system_monitor:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "288B1E9C-52C3-4ACC-807D-F650B850D874"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "ics-cert@hq.dhs.gov"
}