---
cve: "CVE-2012-5863"
severity: "CRITICAL"
cvss: 10.0
epss: "24.8%"
vendor: "Sinapsi"
kev: false
exploited: false
published: "2012-11-23 12:09:58"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-16T01:10:39+02:00"
---

# CVE-2012-5863

> 10.0 CRITICAL · 🧪 PoC

## Beschreibung

These Sinapsi devices do not check for special elements in commands sent 
to the system. By accessing certain pages with administrative privileges
 that do not require authentication within the device, attackers can 
execute arbitrary, unexpected, or dangerous commands directly onto the 
operating system.

## CVSS-Vektor

```
AV:N/AC:L/Au:N/C:C/I:C/A:C
```

## Exploit-Evidenz

- [EDB-21273 — Ezylog Photovoltaic Management Server - Multiple Vulnerabilities](https://www.exploit-db.com/exploits/21273)

## Referenzen

- <http://www.exploit-db.com/exploits/21273/>
- <http://archives.neohapsis.com/archives/bugtraq/2012-09/0045.html>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/80200>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-12-325-01>
- <http://www.sinapsitech.it/default.asp?active_page_id=78&news_id=88>
- <http://www.us-cert.gov/control_systems/pdf/ICSA-12-325-01.pdf>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/80202>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2012-5863) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
