First published: Mon Feb 26 2024(Updated: )
Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
SMA Cluster Controller Firmware | ||
All of | ||
SMA Cluster Controller Firmware | =01.05.01.r | |
SMA Cluster Controller Firmware | ||
All of | ||
SMA Solar Technology AG Webbox Firmware | <=1.61 | |
SMA Sunny Webbox Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1889 is classified as a high severity Cross-Site Request Forgery vulnerability.
To mitigate CVE-2024-1889, ensure that you update your SMA Cluster Controller to the latest version that addresses this vulnerability.
CVE-2024-1889 is associated with Cross-Site Request Forgery (CSRF) attacks.
CVE-2024-1889 affects users of the SMA Cluster Controller running version 01.05.01.R.
An attacker could exploit CVE-2024-1889 to perform actions with the authenticated user's permissions by sending a malicious link.