CVE-2024-50689 is a critical Insecure Direct Object Reference (IDOR) vulnerability affecting SunGrow iSolarCloud versions prior to the October 31, 2024 remediation, specifically within the orgService API model. This flaw allows unauthenticated attackers to access or modify sensitive data due to improper authorization checks, leading to high confidentiality and integrity impacts. With a CVSS score of 9.1, it presents a significant risk, though there is currently no public exploit code or evidence of active exploitation. Despite the lack of public exploits, the vulnerability has garnered notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024-10-31CPE matchmatch criteria | cpe:2.3:a:sungrowpower:isolarcloud:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.