CVE-2024-50684
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2024-50684 is a vulnerability affecting the SunGrow iSolarCloud Android app version 2.1.6.20241017 and earlier. The issue lies in the insecure use of an AES key for encrypting client data, which results in insufficient entropy. Attackers can potentially intercept communications between the mobile app and iSolarCloud and attempt to decrypt the data using the insecure key, putting user information at risk. This vulnerability requires interception of communications and is considered a significant threat to data confidentiality. Users are strongly encouraged to update to the latest app version or contact their provider for assistance in mitigating this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.