Enbw's vulnerability profile centers on its SENEC storage-box product line, which provides residential and small-business energy-storage solutions, with the observed exposure reflecting embedded firmware and device-management security concerns. The recurring weakness classes—cleartext transmission of sensitive information, exposure of resources to wrong network spheres, missing authorization checks, and use of hard-coded credentials—are characteristic of IoT and embedded energy devices where authentication and data-protection mechanisms are often underdeveloped. Live exploitation status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Enbw over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-39169CRITICAL The affected devices use publicly available default credentials with administrative privileges. | Dec 7, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-39167HIGH In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data. | Dec 7, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-39172CRITICAL The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic. | Dec 7, 2023 | 9.1 | 22 | NO | NO |
CVE-2023-39171HIGH SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials. | Dec 7, 2023 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Enbw.
Media articles that mention a CVE ID that affects a product developed by Enbw — matched by CVE ID, not by vendor name.