First published: Wed Feb 26 2025(Updated: )
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sungrow iSolarCloud | <2024-10-31 | |
iSolarCloud | <October 31, 2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-50689 is classified as a medium severity vulnerability due to its potential impact on data integrity and access controls.
To fix CVE-2024-50689, upgrade to the SunGrow iSolarCloud version released after October 31, 2024 that addresses the insecure direct object references.
CVE-2024-50689 involves insecure direct object references (IDOR) via the orgService API model, which can allow unauthorized access to user data.
Any user or organization utilizing SunGrow iSolarCloud versions before October 31, 2024 may be affected by CVE-2024-50689.
CVE-2024-50689 was reported recently and is set to be remediated by October 31, 2024.