SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://en.sungrowpower.com/security-notice-detail-2/6124 |
|
History
Mon, 07 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sungrowpower
Sungrowpower isolarcloud |
|
| CPEs | cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:* | |
| Vendors & Products |
Sungrowpower
Sungrowpower isolarcloud |
Tue, 04 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-295 | |
| Metrics |
cvssV3_1
|
Wed, 26 Feb 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-02-26T00:00:00.000Z
Updated: 2025-03-04T21:15:45.230Z
Reserved: 2024-10-28T00:00:00.000Z
Link: CVE-2024-50691
Updated: 2025-03-04T21:15:36.495Z
Status : Analyzed
Published: 2025-02-26T21:15:17.823
Modified: 2025-04-07T18:50:56.273
Link: CVE-2024-50691
No data.
ReportizFlow