CVE-2024-23785: CSRF
Published Feb 14, 2024
·Updated
Cross-site request forgery vulnerability in Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a remote unauthenticated attacker to change the product settings.
Affected Software
4 affected components
All of the following
SHARP Jh-rvb1 Firmware<=b0.1.9.1
SHARP Jh-rvb1
All of the following
SHARP Jh-rv11 Firmware<=b0.1.9.1
SHARP Jh-rv11
Event History
Feb 14, 2024
CVE Published
via MITRE·10:07 AM
Data Sourced
via MITRE·10:07 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23785?
CVE-2024-23785 is rated as a medium severity vulnerability.
2
How do I mitigate CVE-2024-23785?
To mitigate CVE-2024-23785, update the firmware of the Energy Management Controller to a version later than B0.1.9.1.
3
What products are affected by CVE-2024-23785?
CVE-2024-23785 affects the Sharp Energy Management Controller models JH-RVB1 and JH-RV11 with firmware version B0.1.9.1 or earlier.
4
Can CVE-2024-23785 be exploited remotely?
Yes, CVE-2024-23785 can be exploited remotely by an unauthenticated attacker.
5
What type of vulnerability is CVE-2024-23785?
CVE-2024-23785 is a Cross-site request forgery (CSRF) vulnerability.