Sungrow iSolarCloud Insecure Direct Object Reference Vulnerability in commonService API
Vulnerability
A vulnerability allowing Insecure Direct Object References (IDOR) has been identified in the Sungrow iSolarCloud commonService API, prior to the October 31, 2024 remediation. This vulnerability enables unauthorized access to shared system resources, potentially exposing internal service configurations and operational details.
Impact
Exploitation of this vulnerability could lead to unauthorized access to data and internal service configurations, allowing attackers to retrieve sensitive information about system operations and configurations.
Remediation
Users of iSolarCloud have been automatically upgraded and the vulnerability repaired as of October 31, 2024.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
