CVE Feed

    Dashboard / CVE / CVE-2023-46344

    CVE-2023-46344

    A vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and possibly other Solar-Log Base products, allows an attacker to escalate their privileges by exploiting a stored cross-site scripting (XSS) vulnerability in the switch group function under /#ilang=DE&b=c_smartenergy_swgroups in the web portal. The vulnerability can be exploited to gain the rights of an installer or PM, which can then be used to gain administrative access to the web portal and execute further attacks. NOTE: The vendor states that this vulnerability has been fixed with 3.0.0-60 11.10.2013 for SL 200, 500, 1000 / not existing for SL 250, 300, 1200, 2000, SL 50 Gateway, SL Base.

    Published:Feb 2, 2024
    Last Modified:May 7, 2025
    EPS:Feb 2, 2024
    EPSS Score:0.00181
    CVSS Score:5.4

    Affected Products

    Vendor
    Solar-log
    Product
    2000 Pm\+
    Vendor
    Solar-log
    Product
    2000 Pm\+ Firmware
    Vendor
    Solar Log
    Product
    Base 15 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High