CVE-2024-50691

SunGrow iSolarCloud Android app V2.1.6.20241104 and prior suffers from Missing SSL Certificate Validation. The app explicitly ignores certificate errors and is vulnerable to MiTM attacks. Attackers can impersonate the iSolarCloud server and communicate with the Android app.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:*

History

07 Apr 2025, 18:50

Type Values Removed Values Added
References () https://en.sungrowpower.com/security-notice-detail-2/6124 - () https://en.sungrowpower.com/security-notice-detail-2/6124 - Vendor Advisory
CPE cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:android:*:*
First Time Sungrowpower
Sungrowpower isolarcloud

04 Mar 2025, 22:15

Type Values Removed Values Added
Summary
  • (es) La aplicación SunGrow iSolarCloud para Android V2.1.6.20241104 y versiones anteriores presentan un problema de falta de validación del certificado SSL. La aplicación ignora explícitamente los errores de certificado y es vulnerable a ataques MiTM. Los atacantes pueden hacerse pasar por el servidor iSolarCloud y comunicarse con la aplicación para Android.
CWE CWE-295
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

26 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-26 21:15

Updated : 2025-04-07 18:50


NVD link : CVE-2024-50691

Mitre link : CVE-2024-50691

CVE.ORG link : CVE-2024-50691


JSON object : View

Products Affected

sungrowpower

  • isolarcloud
CWE
CWE-295

Improper Certificate Validation