WE USE COOKIES ON THIS SITE TO ENHANCE YOUR USER EXPERIENCE
By clicking any link on this page you are giving your consent for us to set cookies.
More info
OK, I AGREE
NO, THANKS
|
Online exhibition
|
Online experience Hall
|
|
LANGUAGE
  • HOME
  • ABOUT SUNGROW
  • SOLUTIONS
    PV SYSTEM

    Residential System

    Commercial System

    Utility System

    STORAGE SYSTEM

    Residential Storage System

    Commercial Storage System

    Utility Storage System

    EV CHARGER

    Private PV + ESS + Charger Solution

    Destination Charging

    Public Fast Charging

    FLOATING PV SYSTEM

    Floating PV System

    PV POWER PLANT

    Residential PV Business Unit

    Green Power Business Unit

    WIND PRODUCTS & SOLUTION

    Aftermarket

    FLEXIBLE GREEN HYDROGEN PRODUCTION SYSTEM

    Flexible Green Hydrogen Production System

  • PRODUCTS
    PV SYSTEM

    String Inverter

    Central Inverter

    MLPE

    1+X Modular Inverter

    STORAGE SYSTEM

    MV Power Converter/Hybrid Inverter

    Battery

    Energy Storage System

    EV CHARGER

    AC Charger

    DC Charger

    iEnergyCharge

    iSOLARCLOUD

    Cloud Platform

    Energy Management System

    Intelligent Gateway

    FLOATING PV SYSTEM

    Floating Body

    Inverter & Booster Floating Platform

    ACCESSORY

    Monitoring

    WIND PRODUCTS

    Doubly-fed Wind Converter

    Full Power Converter

    Medium Voltage Converter

    Pitch Drivers

    Grid Simulator

    Motors Drivers

    HYDROGEN EQUIPMENT

    ALK water electrolysis equipment

    PEM water electrolysis equipment

    PWM hydrogen production power supply

    Intelligent hydrogen management system

  • SERVICE & SUPPORT
    ONLINE SERVICE
    CONTACT US
    CONTACT FORM
SEARCH
Guess you want to find it.
Online
exhibition
Online
experience Hall
SEARCH
Guess you want to find it.
COUNTRY

【Security Advisory】Sungrow iSolarCloud – Insecure Direct Object References (IDOR) in orgService API (CVE-2024-50689) (✅mitigated)

The iSolarCloud orgService API is vulnerable to Insecure Direct Object References (IDOR). Attackers can exploit this issue to access and modify organizational data without proper authentication, potentially leading to unauthorized modifications of organization-wide settings, exposure of sensitive business data, and disruption of services.

 

Affected Versions

  • Vulnerable: The iSolarCloud commonService vulnerability, which was      remediated on October 31, 2024, had exposed the system to security risks      before its mitigation.

  • Not Affected: The iSolarCloud commonService vulnerability, which was      remediated on October 31, 2024, has posed no risk to the system since its      resolution.

 

Vulnerability Rating

CVE-2024-506898.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

The scoring is based on the CVSS 3.1 standard. The scoring criteria can be referenced at

https://www.first.org/cvss/calculator/3.1

 

Mitigation and Remediation

  • Recommended Action: The iSolarCloud has been upgraded and repaired on October 31,      2024 without customer action.

  • Patch Release: N/A.

  • Temporary Fix: N/A.

Exploitation Status

No known exploitation in the wild.

Acknowledgments

This vulnerability was discovered and reported by Forescout Technologies.

 

Statement

All software updates, patches, and documentation provided by Sungrow Power Supply Co., Ltd. are the proprietary work of Sungrow. These materials may only be used for product maintenance and security improvements. Any unauthorized modification, distribution, decompilation, or reverse engineering is strictly prohibited.

 

Sungrow makes no express or implied warranties regarding the information provided, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. Sungrow shall not be liable for any direct, indirect, incidental, or consequential damages arising from the use of this document or associated software.

 

Sungrow reserves the right to update or modify this document at any time without prior notice. Customers are responsible for implementing security updates in a timely manner to protect their systems.


18MW PV Plant in Dubai
Developer: Recurrent Energy
Owner: empra
EPC:Signal Energy
Capacity:205MWac
Model:SG2500U
Location:Fresno, CA
Commissioned in Q4 2017
Developer: Recurrent Energy
Owner: empra
EPC:Signal Energy
Capacity:205MWac
Model:SG2500U
Location:Fresno, CA
Commissioned in Q4 2017