CVE-2024-50684

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 26, 2025
Updated: Mar 5, 2025
CWE ID 330

Summary

CVE-2024-50684 is a vulnerability affecting the SunGrow iSolarCloud Android app version 2.1.6.20241017 and earlier. The issue lies in the insecure use of an AES key for encrypting client data, which results in insufficient entropy. Attackers can potentially intercept communications between the mobile app and iSolarCloud and attempt to decrypt the data using the insecure key, putting user information at risk. This vulnerability requires interception of communications and is considered a significant threat to data confidentiality. Users are strongly encouraged to update to the latest app version or contact their provider for assistance in mitigating this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share