SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://en.sungrowpower.com/security-notice-detail-2/6126 |
|
History
Mon, 07 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sungrowpower
Sungrowpower isolarcloud |
|
| CPEs | cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:* | |
| Vendors & Products |
Sungrowpower
Sungrowpower isolarcloud |
Wed, 05 Mar 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-330 | |
| Metrics |
cvssV3_1
|
Wed, 26 Feb 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-26T00:00:00.000Z
Updated: 2025-03-05T14:43:15.756Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-50684
Updated: 2025-03-05T14:43:05.096Z
Status : Analyzed
Published: 2025-02-26T21:15:17.267
Modified: 2025-04-07T18:51:59.260
Link: CVE-2024-50684
No data.
ReportizFlow