5.9
CVE-2024-28756
- EPSS 0.21%
- Veröffentlicht 21.03.2024 21:15:10
- Zuletzt bearbeitet 17.06.2025 13:47:54
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Solaredge ≫ Mysolaredge SwPlatformandroid Version < 2.20.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.112 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| cve@mitre.org | 5.9 | 1.6 | 4.2 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-125 Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
https://www.solaredge.com/coordinated-vulnerability-disclosure-policy/advisories/sedg-2024-1
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-012.txt