First published: Wed Oct 09 2019(Updated: )
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
SMA Solar Technology AG Webbox Firmware | <=1.6 | |
SMA Sunny Webbox Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13529 is considered to have a medium severity rating due to its potential for remote exploitation.
To fix CVE-2019-13529, upgrade the Sunny WebBox firmware to version 1.7 or higher.
CVE-2019-13529 enables remote attackers to perform actions with the permissions of the user through a Cross-Site Request Forgery (CSRF) vulnerability.
CVE-2019-13529 affects users of the Sunny WebBox Firmware Version 1.6 and prior.
The impact of CVE-2019-13529 can lead to unauthorized actions being executed on behalf of authenticated users.