CVE-2024-50684 Details
Description
SunGrow iSolarCloud Android app V2.1.6.20241017 and prior uses an insecure AES key to encrypt client data (insufficient entropy). This may allow attackers to decrypt intercepted communications between the mobile app and iSolarCloud.
A vulnerability exists in the Sungrow iSolarCloud Android app, specifically in versions through 2.1.6.20241017, due to the use of an insecure AES encryption key with insufficient entropy. This weakness may enable attackers to decrypt intercepted communications between the mobile app and the iSolarCloud service, potentially exposing sensitive user information.
Users are advised to update the iSolarCloud Android app to the latest version available in the official app store. A patch has been released. As a temporary fix, users should avoid connecting to untrusted networks and enable VPN encryption when using the app.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 5, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://en.sungrowpower.com/security-notice-detail-2/6126 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-330 | Use of Insufficiently Random Values | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sungrowpower isolarcloud | < 2.1.6.20241104 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2025 | Initial Analysis | [email protected] |
| Mar 5, 2025 | CVE Modified | CISA-ADP |
| Feb 26, 2025 | New CVE Received | [email protected] |