First published: Thu Apr 07 2022(Updated: )
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SMA Sunny Tripower Firmware | =3.10.16.r | |
SMA Sunny Tripower | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46416 is classified as a high severity vulnerability due to insecure direct object reference allowing unauthorized access.
To fix CVE-2021-46416, update the SUNNY TRIPOWER 5.0 Firmware to the latest version that addresses insecure cookie handling.
CVE-2021-46416 specifically affects SUNNY TRIPOWER firmware version 3.10.16.R.
The vulnerability in CVE-2021-46416 is caused by insecure direct object references due to improper cookie handling.
Yes, unauthorized user groups can exploit CVE-2021-46416 to gain access because of the insecure handling of cookies.