CVE-2017-20021: Solar-Log 1000 Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

A vulnerability, which was classified as critical, was found in Solare Solar-Log 2.8.4-56/3.5.2-85. This affects an unknown part of the component File Upload. The manipulation leads to privilege escalation. It is possible to initiate the attack remotely. Upgrading to version 3.5.3-86 is able to address this issue. It is recommended to upgrade the affected component.

Affected products

  • Solar-Log Solar-Log 1000 Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 1000 Pm+ Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 1200 Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 2000 Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 250 Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 300 Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 500 Firmware: version 2.8.4-56 only; version 3.5.2-85 only
  • Solar-Log Solar-Log 800e Firmware: version 2.8.4-56 only; version 3.5.2-85 only

Published 2022-06-09. Last modified 2026-06-17.