Enphase Installer Toolkit Android App Use of Hard-coded Credentials
Vulnerability Description
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-32274
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- OBSWCY3F reported this vulnerability to CISA.
More from Enphase
View All →Affected Vendor
Enphase
View all reports →