CVE-2024-50688
Last modified
CVE-2024-50688 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user account) and the cloud uses the same MQTT credentials for exchanging the device telemetry.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sungrowpower | Isolarcloud | < 2.1.6.20241104 |
References
- https://en.sungrowpower.com/security-notice-detail-2/6122Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-50688?
How severe is CVE-2024-50688?
How do I fix CVE-2024-50688?
Are you affected by CVE-2024-50688?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
