8.8
CVSSv3

CVE-2017-9863

Published: 05/08/2017 Updated: 17/05/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Vulnerable Product Search on Vulmon Subscribe to Product

sma sunny_boy_3600_firmware -

sma sunny_boy_5000_firmware -

sma sunny_tripower_core1_firmware -

sma sunny_tripower_15000tl_firmware -

sma sunny_tripower_20000tl_firmware -

sma sunny_tripower_25000tl_firmware -

sma sunny_tripower_5000tl_firmware -

sma sunny_tripower_12000tl_firmware -

sma sunny_tripower_60_firmware -

sma sunny_boy_3000tl_firmware -

sma sunny_boy_3600tl_firmware -

sma sunny_boy_4000tl_firmware -

sma sunny_boy_5000tl_firmware -

sma sunny_boy_1.5_firmware -

sma sunny_boy_2.5_firmware -

sma sunny_boy_3.0_firmware -

sma sunny_boy_3.6_firmware -

sma sunny_boy_4.0_firmware -

sma sunny_boy_5.0_firmware -

sma sunny_central_2200_firmware -

sma sunny_central_1000cp_xt_firmware -

sma sunny_central_800cp_xt_firmware -

sma sunny_central_850cp_xt_firmware -

sma sunny_central_900cp_xt_firmware -

sma sunny_central_500cp_xt_firmware -

sma sunny_central_630cp_xt_firmware -

sma sunny_central_720cp_xt_firmware -

sma sunny_central_760cp_xt_firmware -

sma sunny_central_storage_500_firmware -

sma sunny_central_storage_630_firmware -

sma sunny_central_storage_720_firmware -

sma sunny_central_storage_760_firmware -

sma sunny_central_storage_800_firmware -

sma sunny_central_storage_850_firmware -

sma sunny_central_storage_900_firmware -

sma sunny_central_storage_1000_firmware -

sma sunny_central_storage_2200_firmware -

sma sunny_central_storage_2500-ev_firmware -

sma sunny_boy_storage_2.5_firmware -

sma sunny explorer -