CVE-2024-1890

Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sma:sunny_webbox:*:*:*:*:*:*:*:*

History

11 Mar 2025, 14:51

Type Values Removed Values Added
CPE cpe:2.3:h:sma:cluster_controller:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:cluster_controller_firmware:01.05.01.r:*:*:*:*:*:*:*

27 Feb 2025, 22:03

Type Values Removed Values Added
CPE cpe:2.3:h:sma:cluster_controller:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:cluster_controller_firmware:01.05.01.r:*:*:*:*:*:*:*
cpe:2.3:h:sma:sunny_webbox:*:*:*:*:*:*:*:*
cpe:2.3:o:sma:sunny_webbox_firmware:*:*:*:*:*:*:*:*
First Time Sma cluster Controller
Sma cluster Controller Firmware
Sma sunny Webbox
Sma sunny Webbox Firmware
Sma
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products - Third Party Advisory

21 Nov 2024, 08:51

Type Values Removed Values Added
References () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products - () https://www.incibe.es/en/incibe-cert/notices/aviso-sci/multiple-vulnerabilities-sma-products -

21 Mar 2024, 02:51

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad por la cual un atacante podría enviar un enlace malicioso a un operador autenticado, lo que podría permitir a atacantes remotos realizar un ataque de clickjacking en la versión de firmware 1.6.1 y anteriores de Sunny WebBox.

26 Feb 2024, 16:32

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-26 16:27

Updated : 2025-03-11 14:51


NVD link : CVE-2024-1890

Mitre link : CVE-2024-1890

CVE.ORG link : CVE-2024-1890


JSON object : View

Products Affected

sma

  • sunny_webbox
  • sunny_webbox_firmware
CWE
CWE-1021

Improper Restriction of Rendered UI Layers or Frames