Vulnerability Description
An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can be used on any SMA inverter. Any such code, when combined with the installer account, allows changing very sensitive parameters. NOTE: the vendor reports that Grid Guard is not an authentication feature; it is only a tracing feature. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sma | Sunny Boy 3600 Firmware | - |
| Sma | Sunny Boy 3600 | - |
| Sma | Sunny Boy 5000 Firmware | - |
| Sma | Sunny Boy 5000 | - |
| Sma | Sunny Tripower Core1 Firmware | - |
| Sma | Sunny Tripower Core1 | - |
| Sma | Sunny Tripower 15000Tl Firmware | - |
| Sma | Sunny Tripower 15000Tl | - |
| Sma | Sunny Tripower 20000Tl Firmware | - |
| Sma | Sunny Tripower 20000Tl | - |
| Sma | Sunny Tripower 25000Tl Firmware | - |
| Sma | Sunny Tripower 25000Tl | - |
| Sma | Sunny Tripower 5000Tl Firmware | - |
| Sma | Sunny Tripower 5000Tl | - |
| Sma | Sunny Tripower 12000Tl Firmware | - |
| Sma | Sunny Tripower 12000Tl | - |
| Sma | Sunny Tripower 60 Firmware | - |
| Sma | Sunny Tripower 60 | - |
| Sma | Sunny Boy 3000Tl Firmware | - |
| Sma | Sunny Boy 3000Tl | - |
Related Weaknesses (CWE)
References
- http://www.sma.de/en/statement-on-cyber-security.html
- http://www.sma.de/fileadmin/content/global/specials/documents/cyber-security/Whi
- https://horusscenario.com/CVE-information/Third Party Advisory
- http://www.sma.de/en/statement-on-cyber-security.html
- http://www.sma.de/fileadmin/content/global/specials/documents/cyber-security/Whi
- https://horusscenario.com/CVE-information/Third Party Advisory
FAQ
What is CVE-2017-9855?
CVE-2017-9855 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single G...
How severe is CVE-2017-9855?
CVE-2017-9855 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-9855?
Check the references section above for vendor advisories and patch information. Affected products include: Sma Sunny Boy 3600 Firmware, Sma Sunny Boy 3600, Sma Sunny Boy 5000 Firmware, Sma Sunny Boy 5000, Sma Sunny Tripower Core1 Firmware.