CVE-2024-50691
Last modified
CVE-2024-50691 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sungrowpower | Isolarcloud | < 2.1.6.20241115 |
References
- https://en.sungrowpower.com/security-notice-detail-2/6124Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-50691?
How severe is CVE-2024-50691?
How do I fix CVE-2024-50691?
Are you affected by CVE-2024-50691?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
