CVE-2017-9857

HIGH

SMA Solar Technology - Info Disclosure

Title source: llm
STIX 2.1

Description

An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay attacks. Any setting change, authentication packet, scouting packet, etc. can be replayed, injected, or used for a man in the middle session. All functionalities available in Sunny Explorer can effectively be done from anywhere within the network as long as an attacker gets the packet setup correctly. This includes the authentication process for all (including hidden) access levels and the changing of settings in accordance with the gained access rights. Furthermore, because the SMAdata2+ communication channel is unencrypted, an attacker capable of understanding the protocol can eavesdrop on communications. NOTE: the vendor's position is that authentication with encryption is not required on an isolated subnetwork. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

References (3)

Core 3

Scores

CVSS v3 8.1
EPSS 0.0069
EPSS Percentile 48.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-287
Status published
Products (39)
sma/sunny_boy_1.5_firmware
sma/sunny_boy_2.5_firmware
sma/sunny_boy_3.0_firmware
sma/sunny_boy_3.6_firmware
sma/sunny_boy_3000tl_firmware
sma/sunny_boy_3600_firmware
sma/sunny_boy_3600tl_firmware
sma/sunny_boy_4.0_firmware
sma/sunny_boy_4000tl_firmware
sma/sunny_boy_5.0_firmware
... and 29 more
Published Aug 05, 2017
Tracked Since Feb 18, 2026