PT-2024-22564 · Solaredge · Mysolaredge

Tobias Jäger

·

Published

2024-03-21

·

Updated

2024-08-28

·

CVE-2024-28756

CVSS v3.1

5.9

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions SolarEdge mySolarEdge application version prior to 2.20.1 for Android
Description The issue is related to a certificate verification problem, allowing a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server. This could potentially expose sensitive information.
Recommendations For versions prior to 2.20.1, update to version 2.20.1 or later to resolve the issue. As a temporary workaround, consider restricting network access to trusted sources to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-28756

Affected Products

Mysolaredge