CVE-2024-50684
Last modified
CVE-2024-50684 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sungrowpower | Isolarcloud | < 2.1.6.20241104 |
References
- https://en.sungrowpower.com/security-notice-detail-2/6126Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-50684?
How severe is CVE-2024-50684?
How do I fix CVE-2024-50684?
Are you affected by CVE-2024-50684?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
