CRITICAL · 9.8

CVE-2017-9859

An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked relati...

Vulnerability Description

An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked relatively easily. An attacker will likely be able to crack the password using offline crackers. This cracked password can then be used to register at the SMA servers. NOTE: the vendor's position is that "we consider the probability of the success of such manipulation to be extremely low." Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

CVSS Score

9.8

CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SmaSunny Boy 3600 Firmware-
SmaSunny Boy 3600-
SmaSunny Boy 5000 Firmware-
SmaSunny Boy 5000-
SmaSunny Tripower Core1 Firmware-
SmaSunny Tripower Core1-
SmaSunny Tripower 15000Tl Firmware-
SmaSunny Tripower 15000Tl-
SmaSunny Tripower 20000Tl Firmware-
SmaSunny Tripower 20000Tl-
SmaSunny Tripower 25000Tl Firmware-
SmaSunny Tripower 25000Tl-
SmaSunny Tripower 5000Tl Firmware-
SmaSunny Tripower 5000Tl-
SmaSunny Tripower 12000Tl Firmware-
SmaSunny Tripower 12000Tl-
SmaSunny Tripower 60 Firmware-
SmaSunny Tripower 60-
SmaSunny Boy 3000Tl Firmware-
SmaSunny Boy 3000Tl-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-9859?

CVE-2017-9859 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in SMA Solar Technology products. The inverters make use of a weak hashing algorithm to encrypt the password for REGISTER requests. This hashing algorithm can be cracked relati...

How severe is CVE-2017-9859?

CVE-2017-9859 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-9859?

Check the references section above for vendor advisories and patch information. Affected products include: Sma Sunny Boy 3600 Firmware, Sma Sunny Boy 3600, Sma Sunny Boy 5000 Firmware, Sma Sunny Boy 5000, Sma Sunny Tripower Core1 Firmware.