top of page
perceptive_background_267k.jpg

SolisCloud Monitoring Platform

Published:

4 December 2025 at 12:00:00

Alert date:

5 December 2025 at 08:03:22

Source:

cisa.gov

Click to open the original link from this advisory

CISA advisory warns of a critical authorization bypass vulnerability (CVE-2025-13932) in SolisCloud Monitoring Platform APIs. The vulnerability allows authenticated users to access sensitive data from any plant by manipulating plant_id parameters in API requests. This affects both Cloud API and Device Control API versions 1 and 2, with CVSS scores of 7.7 (v3.1) and 8.3 (v4). The vulnerability enables Insecure Direct Object Reference (IDOR) attacks against energy sector infrastructure worldwide. SolisCloud has not responded to CISA's coordination efforts for mitigation.

Technical details

Mitigation steps:

Affected products:

SolisCloud Monitoring Platform

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page