CVE-2024-1889

Cross-Site Request Forgery vulnerability in SMA Cluster Controller, affecting version 01.05.01.R. This vulnerability could allow an attacker to send a malicious link to an authenticated user to perform actions with these user permissions on the affected device.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sma:clcon-10_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:clcon-10:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:sma:clcon-s-10_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:clcon-s-10:-:*:*:*:*:*:*:*

History

11 Mar 2025, 14:51

Type Values Removed Values Added
CPE cpe:2.3:h:sma:cluster_controller:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:cluster_controller_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:sunny_webbox:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:clcon-s-10_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:clcon-s-10:-:*:*:*:*:*:*:*
cpe:2.3:o:sma:clcon-10_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:clcon-10:-:*:*:*:*:*:*:*
First Time Sma clcon-10 Firmware
Sma clcon-10
Sma clcon-s-10
Sma clcon-s-10 Firmware

27 Feb 2025, 22:03

Type Values Removed Values Added
First Time Sma cluster Controller
Sma cluster Controller Firmware
Sma sunny Webbox
Sma sunny Webbox Firmware
Sma
CPE cpe:2.3:h:sma:cluster_controller:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:cluster_controller_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:sunny_webbox:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:*
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products - Third Party Advisory

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products -

21 Mar 2024, 02:51

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de Cross Site Request Forgery en SMA Cluster Controller, que afecta a la versión 01.05.01.R. Esta vulnerabilidad podría permitir a un atacante enviar un enlace malicioso a un usuario autenticado para realizar acciones con estos permisos de usuario en el dispositivo afectado.

26 Feb 2024, 16:32

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-26 16:27

Updated : 2025-03-11 14:51


NVD link : CVE-2024-1889

Mitre link : CVE-2024-1889

CVE.ORG link : CVE-2024-1889


JSON object : View

Products Affected

sma

  • clcon-10
  • clcon-s-10_firmware
  • clcon-10_firmware
  • clcon-s-10
CWE
CWE-352

Cross-Site Request Forgery (CSRF)