CVE-2024-50696: High severity sungrow winet-s vulnerability
SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-50696?
CVE-2024-50696 is classified as high severity due to its potential for allowing unauthorized firmware upgrades.
How do I fix CVE-2024-50696?
To mitigate the risks from CVE-2024-50696, ensure your firmware is updated to a version later than V200.001.00.P025 which addresses the vulnerability.
What systems are affected by CVE-2024-50696?
CVE-2024-50696 affects SunGrow WiNet-S versions V200.001.00.P025 and earlier.
What type of attack does CVE-2024-50696 enable?
CVE-2024-50696 enables attackers to exploit the lack of integrity checks for firmware upgrades, allowing for the installation of malicious firmware.
Is there a patch available for CVE-2024-50696?
Yes, a patch has been released to address CVE-2024-50696; upgrading to the latest firmware version will resolve the vulnerability.