CVE-2024-28756: Medium severity mysolaredge vulnerability
Published Mar 21, 2024
·Updated
The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server.
Affected Software
2 affected components
SolarEdge mySolarEdge<2.20.1
SolarEdge Mysolaredge Android<2.20.1
Event History
Mar 21, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-28756?
CVE-2024-28756 is considered a high severity vulnerability due to its potential to allow MitM attacks.
2
How do I fix CVE-2024-28756?
To resolve CVE-2024-28756, update the SolarEdge mySolarEdge application to version 2.20.1 or later.
3
What type of attack does CVE-2024-28756 enable?
CVE-2024-28756 enables a Machine-in-the-Middle (MitM) attack that can compromise network traffic.
4
What software is affected by CVE-2024-28756?
CVE-2024-28756 affects the SolarEdge mySolarEdge application versions prior to 2.20.1.
5
What is the main issue described in CVE-2024-28756?
The main issue in CVE-2024-28756 is a certificate verification flaw that can expose sensitive network traffic.