CVE-2024-50685

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Feb 26, 2025
Updated: Mar 4, 2025
CWE ID 639

Summary

CVE-2024-50685 is a newly disclosed vulnerability affecting SunGrow iSolarCloud before the scheduled remediation on October 31, 2024. This issue involves insecure direct object references (IDOR) in the powerStationService API model. Hackers can exploit this IDOR vulnerability to gain unauthorized access to sensitive data or take control of certain functionalities within the system. Successful exploitation could lead to significant consequences, including system compromise or data theft. It is crucial for SunGrow iSolarCloud users to apply the forthcoming patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share