CVE-2024-50689: Critical severity sungrow isolarcloud vulnerability
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the orgService API model.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50689?
CVE-2024-50689 is classified as a medium severity vulnerability due to its potential impact on data integrity and access controls.
How do I fix CVE-2024-50689?
To fix CVE-2024-50689, upgrade to the SunGrow iSolarCloud version released after October 31, 2024 that addresses the insecure direct object references.
What does CVE-2024-50689 involve?
CVE-2024-50689 involves insecure direct object references (IDOR) via the orgService API model, which can allow unauthorized access to user data.
Who is affected by CVE-2024-50689?
Any user or organization utilizing SunGrow iSolarCloud versions before October 31, 2024 may be affected by CVE-2024-50689.
When was CVE-2024-50689 reported?
CVE-2024-50689 was reported recently and is set to be remediated by October 31, 2024.