Unprotected Server-side Request Forgery Vulnerability in Energy Management Controller
CVE-2024-23788

8.1HIGH

Key Information:

Vendor
CVE Published:
14 February 2024

Summary

A vulnerability exists in Sharp's Energy Management Controller with Cloud Services, specifically in the JH-RVB1 and JH-RV11 models, versions B0.1.9.1 and earlier. This server-side request forgery vulnerability permits a network-adjacent unauthenticated attacker to send arbitrary HTTP GET requests from the affected devices. The exploitation of this vulnerability may lead to unauthorized actions on behalf of the vulnerable system, posing potential risks to network security and data integrity.

Affected Version(s)

Energy Management Controller with Cloud Services JH-RVB1 Ver.B0.1.9.1 and earlier

Energy Management Controller with Cloud Services JH-RV11 Ver.B0.1.9.1 and earlier

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.