๐Ÿ” CVE Alert

CVE-2024-28756

MEDIUM 5.9
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server.

Vendor n/a
Product n/a
Published Mar 21, 2024
Last Updated Aug 28, 2024
Stay Ahead of the Next One

Get instant alerts for n/a n/a

Be the first to know when new medium vulnerabilities affecting n/a n/a are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AC:H/AV:A/A:N/C:H/I:L/PR:N/S:U/UI:N
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

n/a / n/a
n/a

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
syss.de: https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-012.txt solaredge.com: https://www.solaredge.com/coordinated-vulnerability-disclosure-policy/advisories/sedg-2024-1