8.1
CVSSv3

CVE-2017-9857

Published: 05/08/2017 Updated: 04/06/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.9 | Exploitability Score: 2.2
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay attacks. Any setting change, authentication packet, scouting packet, etc. can be replayed, injected, or used for a man in the middle session. All functionalities available in Sunny Explorer can effectively be done from anywhere within the network as long as an attacker gets the packet setup correctly. This includes the authentication process for all (including hidden) access levels and the changing of settings in accordance with the gained access rights. Furthermore, because the SMAdata2+ communication channel is unencrypted, an attacker capable of understanding the protocol can eavesdrop on communications. NOTE: the vendor's position is that authentication with encryption is not required on an isolated subnetwork. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Vulnerable Product Search on Vulmon Subscribe to Product

sma sunny_boy_3600_firmware -

sma sunny_boy_5000_firmware -

sma sunny_tripower_core1_firmware -

sma sunny_tripower_15000tl_firmware -

sma sunny_tripower_20000tl_firmware -

sma sunny_tripower_25000tl_firmware -

sma sunny_tripower_5000tl_firmware -

sma sunny_tripower_12000tl_firmware -

sma sunny_tripower_60_firmware -

sma sunny_boy_3000tl_firmware -

sma sunny_boy_3600tl_firmware -

sma sunny_boy_4000tl_firmware -

sma sunny_boy_5000tl_firmware -

sma sunny_boy_1.5_firmware -

sma sunny_boy_2.5_firmware -

sma sunny_boy_3.0_firmware -

sma sunny_boy_3.6_firmware -

sma sunny_boy_4.0_firmware -

sma sunny_boy_5.0_firmware -

sma sunny_central_2200_firmware -

sma sunny_central_1000cp_xt_firmware -

sma sunny_central_800cp_xt_firmware -

sma sunny_central_850cp_xt_firmware -

sma sunny_central_900cp_xt_firmware -

sma sunny_central_500cp_xt_firmware -

sma sunny_central_630cp_xt_firmware -

sma sunny_central_720cp_xt_firmware -

sma sunny_central_760cp_xt_firmware -

sma sunny_central_storage_500_firmware -

sma sunny_central_storage_630_firmware -

sma sunny_central_storage_720_firmware -

sma sunny_central_storage_760_firmware -

sma sunny_central_storage_800_firmware -

sma sunny_central_storage_850_firmware -

sma sunny_central_storage_900_firmware -

sma sunny_central_storage_1000_firmware -

sma sunny_central_storage_2200_firmware -

sma sunny_central_storage_2500-ev_firmware -

sma sunny_boy_storage_2.5_firmware -