CVE-2024-50693: Critical severity sungrow isolarcloud vulnerability
Published Feb 26, 2025
·Updated
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
Affected Software
2 affected components
Sungrowpower Isolarcloud<2024-10-31
SunGrow iSolarCloud<October 31, 2024
Event History
Feb 26, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-50693?
CVE-2024-50693 is classified as a medium severity vulnerability due to its potential impact on user data confidentiality.
2
How do I fix CVE-2024-50693?
To remediate CVE-2024-50693, upgrade SunGrow iSolarCloud to a version released after October 31, 2024.
3
What type of vulnerability is CVE-2024-50693?
CVE-2024-50693 is categorized as an Insecure Direct Object Reference (IDOR) vulnerability.
4
Who is affected by CVE-2024-50693?
Any users of SunGrow iSolarCloud versions released before October 31, 2024 are affected by CVE-2024-50693.
5
What can attackers achieve with CVE-2024-50693?
Attackers exploiting CVE-2024-50693 can potentially access unauthorized data through the userService API model.