CVE-2021-46416: High severity SMA Sunny Tripower Firmware vulnerability
Published Apr 7, 2022
·Updated
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
Affected Software
4 affected components
SMA Sunny Tripower Firmware=3.10.16.r
SMA Sunny Tripower=5.0
All of the following
SMA Sunny Tripower Firmware=3.10.16.r
SMA Sunny Tripower=5.0
Event History
Apr 7, 2022
CVE Published
via MITRE·10:45 AM
Data Sourced
via MITRE·10:45 AM
Description
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-46416?
CVE-2021-46416 is classified as a high severity vulnerability due to insecure direct object reference allowing unauthorized access.
2
How do I fix CVE-2021-46416?
To fix CVE-2021-46416, update the SUNNY TRIPOWER 5.0 Firmware to the latest version that addresses insecure cookie handling.
3
What software versions are affected by CVE-2021-46416?
CVE-2021-46416 specifically affects SUNNY TRIPOWER firmware version 3.10.16.R.
4
What causes the vulnerability in CVE-2021-46416?
The vulnerability in CVE-2021-46416 is caused by insecure direct object references due to improper cookie handling.
5
Can unauthorized users exploit CVE-2021-46416?
Yes, unauthorized user groups can exploit CVE-2021-46416 to gain access because of the insecure handling of cookies.