Vulnerability Description
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sungrowpower | Isolarcloud | < 2024-10-31 |
Related Weaknesses (CWE)
References
- https://en.sungrowpower.com/security-notice-detail-2/6112Vendor Advisory
FAQ
What is CVE-2024-50686?
CVE-2024-50686 is a vulnerability with a CVSS score of 9.1 (CRITICAL). SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the commonService API model.
How severe is CVE-2024-50686?
CVE-2024-50686 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-50686?
Check the references section above for vendor advisories and patch information. Affected products include: Sungrowpower Isolarcloud.