Unprotected Server-side Request Forgery Vulnerability in Energy Management Controller
CVE-2024-23788
8.1HIGH
Summary
A vulnerability exists in Sharp's Energy Management Controller with Cloud Services, specifically in the JH-RVB1 and JH-RV11 models, versions B0.1.9.1 and earlier. This server-side request forgery vulnerability permits a network-adjacent unauthenticated attacker to send arbitrary HTTP GET requests from the affected devices. The exploitation of this vulnerability may lead to unauthorized actions on behalf of the vulnerable system, posing potential risks to network security and data integrity.
Affected Version(s)
Energy Management Controller with Cloud Services JH-RVB1 Ver.B0.1.9.1 and earlier
Energy Management Controller with Cloud Services JH-RV11 Ver.B0.1.9.1 and earlier
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved