PT-2024-20085 · Sharp · Sharp Energy Management Controller

Shoji Baba

·

Published

2024-01-31

·

Updated

2025-03-18

·

CVE-2024-23786

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SHARP Energy Management Controller with Cloud Services versions B0.1.9.1 and earlier
Description A cross-site scripting issue allows a network-adjacent unauthenticated attacker to execute an arbitrary script on the web browser of the user accessing the management page of the affected product.
Recommendations For versions B0.1.9.1 and earlier, update to a version later than B0.1.9.1 to resolve the issue. As a temporary workaround, consider restricting access to the management page of the affected product until a patch is available.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-23786

Affected Products

Sharp Energy Management Controller