PT-2022-12692 · Sma Solar Technology · Sunny Tripower 5.0

Published

2022-04-07

·

Updated

2022-04-15

·

CVE-2021-46416

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R
Description The issue is related to an insecure direct object reference, which allows unauthorized user groups to access due to insecure cookie handling.
Recommendations For SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R, consider updating the firmware to a version that addresses the insecure cookie handling issue as a permanent solution. As a temporary workaround, restrict access to sensitive user groups and ensure proper cookie handling mechanisms are in place to minimize the risk of exploitation.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-46416

Affected Products

Sunny Tripower 5.0