Логотип exploitDog
bind:CVE-2024-50696
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-50696

Количество 2

Количество 2

nvd логотип

CVE-2024-50696

12 месяцев назад

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2c82-m7qw-rh64

12 месяцев назад

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-50696

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

CVSS3: 7.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-2c82-m7qw-rh64

SunGrow WiNet-S V200.001.00.P025 and earlier versions is missing integrity checks for firmware upgrades. Sending a specific MQTT message allows an update to an inverter or a WiNet connectivity dongle with a bogus firmware file that is located on attacker-controlled server.

CVSS3: 7.5
0%
Низкий
12 месяцев назад

Уязвимостей на страницу