The SolarEdge mySolarEdge application before 2.20.1 for Android has a certificate verification issue that allows a Machine-in-the-middle (MitM) attacker to read and alter all network traffic between the application and the server.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-012.txt | exploit third party advisory |
https://www.solaredge.com/coordinated-vulnerability-disclosure-policy/advisories/sedg-2024-1 | vendor advisory |