Unprotected Server-side Request Forgery Vulnerability in Energy Management Controller
CVE-2024-23788
8.1HIGH
What is CVE-2024-23788?
A vulnerability exists in Sharp's Energy Management Controller with Cloud Services, specifically in the JH-RVB1 and JH-RV11 models, versions B0.1.9.1 and earlier. This server-side request forgery vulnerability permits a network-adjacent unauthenticated attacker to send arbitrary HTTP GET requests from the affected devices. The exploitation of this vulnerability may lead to unauthorized actions on behalf of the vulnerable system, posing potential risks to network security and data integrity.
Affected Version(s)
Energy Management Controller with Cloud Services JH-RVB1 Ver.B0.1.9.1 and earlier
Energy Management Controller with Cloud Services JH-RV11 Ver.B0.1.9.1 and earlier