CVE-2024-50695
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-50695 is a newly disclosed vulnerability affecting SunGrow WiNet-SV200.001.00.P027 and older versions. The issue stems from an absence of bounds checks on MQTT (Message Queuing Telemetry Transport) topics, leading to a stack-based buffer overflow. Successful exploitation of this vulnerability may result in code injection and subsequent unauthorized control over affected systems. This weakness could potentially allow attackers to execute arbitrary commands or gain elevated privileges. It is recommended that users update their SunGrow WiNet firmware to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.