CVE-2024-50697

In SunGrow WiNet-SV200.001.00.P027 and earlier versions, when decrypting MQTT messages, the code that parses specific TLV fields does not have sufficient bounds checks. This may result in a stack-based buffer overflow.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:sungrowpower:winet-s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:sungrowpower:winet-s:-:*:*:*:*:*:*:*

History

29 May 2025, 16:02

Type Values Removed Values Added
References () https://en.sungrowpower.com/security-notice-detail-2/5961 - () https://en.sungrowpower.com/security-notice-detail-2/5961 - Vendor Advisory
First Time Sungrowpower winet-s
Sungrowpower winet-s Firmware
Sungrowpower
CPE cpe:2.3:h:sungrowpower:winet-s:-:*:*:*:*:*:*:*
cpe:2.3:o:sungrowpower:winet-s_firmware:*:*:*:*:*:*:*:*

27 Jan 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) En SunGrow WiNet-SV200.001.00.P027 y versiones anteriores, al descifrar mensajes MQTT, el código que analiza campos TLV específicos no tiene suficientes comprobaciones de los límites. Esto puede provocar un desbordamiento del búfer basado en la pila.
CWE CWE-120

24 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-24 23:15

Updated : 2025-05-29 16:02


NVD link : CVE-2024-50697

Mitre link : CVE-2024-50697

CVE.ORG link : CVE-2024-50697


JSON object : View

Products Affected

sungrowpower

  • winet-s
  • winet-s_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')