CRITICAL · 9.8

CVE-2017-9854

An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. Thes...

Vulnerability Description

An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. These passwords can then be used to compromise the overall device. NOTE: the vendor reports that exploitation likelihood is low because these packets are usually sent only once during installation. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SmaSunny Boy 3600 Firmware-
SmaSunny Boy 3600-
SmaSunny Boy 5000 Firmware-
SmaSunny Boy 5000-
SmaSunny Tripower Core1 Firmware-
SmaSunny Tripower Core1-
SmaSunny Tripower 15000Tl Firmware-
SmaSunny Tripower 15000Tl-
SmaSunny Tripower 20000Tl Firmware-
SmaSunny Tripower 20000Tl-
SmaSunny Tripower 25000Tl Firmware-
SmaSunny Tripower 25000Tl-
SmaSunny Tripower 5000Tl Firmware-
SmaSunny Tripower 5000Tl-
SmaSunny Tripower 12000Tl Firmware-
SmaSunny Tripower 12000Tl-
SmaSunny Tripower 60 Firmware-
SmaSunny Tripower 60-
SmaSunny Boy 3000Tl Firmware-
SmaSunny Boy 3000Tl-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-9854?

CVE-2017-9854 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in SMA Solar Technology products. By sniffing for specific packets on the localhost, plaintext passwords can be obtained as they are typed into Sunny Explorer by the user. Thes...

How severe is CVE-2017-9854?

CVE-2017-9854 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-9854?

Check the references section above for vendor advisories and patch information. Affected products include: Sma Sunny Boy 3600 Firmware, Sma Sunny Boy 3600, Sma Sunny Boy 5000 Firmware, Sma Sunny Boy 5000, Sma Sunny Tripower Core1 Firmware.