First published: Mon Feb 26 2024(Updated: )
Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
SMA Sunny WebBox | <1.6.1 | |
All of | ||
SMA Cluster Controller Firmware | =01.05.01.r | |
SMA Cluster Controller Firmware | ||
All of | ||
SMA Solar Technology AG Webbox Firmware | <=1.61 | |
SMA Sunny Webbox Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1890 is considered a medium severity vulnerability due to its potential for clickjacking attacks on affected devices.
To mitigate CVE-2024-1890, upgrade to Sunny WebBox firmware version 1.6.2 or later, which contains the necessary security fixes.
CVE-2024-1890 affects Sunny WebBox firmware versions 1.6.1 and earlier.
CVE-2024-1890 allows attackers to perform clickjacking attacks by tricking authenticated users into clicking malicious links.
Yes, CVE-2024-1890 requires an authenticated operator to be targeted for the clickjacking attack to be successful.