Files
CVEs-PoC/2012/CVE-2012-5863.md
T
2025-09-29 21:09:30 +02:00

20 lines
964 B
Markdown

### [CVE-2012-5863](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-5863)
![](https://img.shields.io/static/v1?label=Product&message=eSolar%20DUO&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=eSolar%20Light&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=eSolar&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-78&color=brightgreen)
### Description
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.
### POC
#### Reference
- https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01
#### Github
No PoCs found on GitHub currently.