Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-50696

Опубликовано: 26 фев. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:sungrowpower:winet-s_firmware:*:*:*:*:*:*:*:*
Версия до 200.001.00.P025 (включая)
cpe:2.3:h:sungrowpower:winet-s:-:*:*:*:*:*:*:*

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-494

Связанные уязвимости

CVSS3: 7.5
github
12 месяцев назад

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

EPSS

Процентиль: 19%
0.0006
Низкий

7.5 High

CVSS3

Дефекты

CWE-494