Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2024-1890
Disclosure Date: February 26, 2024 (last updated February 28, 2025)
Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
0
Attacker Value
Unknown
CVE-2024-1889
Disclosure Date: February 26, 2024 (last updated February 28, 2025)
Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.
0
Attacker Value
Unknown
CVE-2019-13529
Disclosure Date: October 09, 2019 (last updated November 27, 2024)
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform actions with the permissions of the user on the Sunny WebBox Firmware Version 1.6 and prior. This device uses IP addresses to maintain communication after a successful login, which would increase the ease of exploitation.
0
Attacker Value
Unknown
CVE-2015-3964
Disclosure Date: September 11, 2015 (last updated October 05, 2023)
SMA Solar Sunny WebBox has hardcoded passwords, which makes it easier for remote attackers to obtain access via unspecified vectors.
0