HIGH · 7.5

CVE-2017-9864

An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authenticated in any way. This changes the system time, possibly affecting lockout policie...

Vulnerability Description

An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authenticated in any way. This changes the system time, possibly affecting lockout policies and random-number generators based on timestamps, and makes timestamps for data analysis unreliable. NOTE: the vendor reports that this is largely irrelevant because it only affects log-entry timestamps, and because the plant time would later be reset via NTP. (It has never been the case that a lockout policy or random-number generator was affected.) Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

CVSS Score

7.5

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SmaSunny Boy 3600 Firmware-
SmaSunny Boy 3600-
SmaSunny Boy 5000 Firmware-
SmaSunny Boy 5000-
SmaSunny Tripower Core1 Firmware-
SmaSunny Tripower Core1-
SmaSunny Tripower 15000Tl Firmware-
SmaSunny Tripower 15000Tl-
SmaSunny Tripower 20000Tl Firmware-
SmaSunny Tripower 20000Tl-
SmaSunny Tripower 25000Tl Firmware-
SmaSunny Tripower 25000Tl-
SmaSunny Tripower 5000Tl Firmware-
SmaSunny Tripower 5000Tl-
SmaSunny Tripower 12000Tl Firmware-
SmaSunny Tripower 12000Tl-
SmaSunny Tripower 60 Firmware-
SmaSunny Tripower 60-
SmaSunny Boy 3000Tl Firmware-
SmaSunny Boy 3000Tl-

References

FAQ

What is CVE-2017-9864?

CVE-2017-9864 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in SMA Solar Technology products. An attacker can change the plant time even when not authenticated in any way. This changes the system time, possibly affecting lockout policie...

How severe is CVE-2017-9864?

CVE-2017-9864 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2017-9864?

Check the references section above for vendor advisories and patch information. Affected products include: Sma Sunny Boy 3600 Firmware, Sma Sunny Boy 3600, Sma Sunny Boy 5000 Firmware, Sma Sunny Boy 5000, Sma Sunny Tripower Core1 Firmware.