CVE-2017-9852

UnknownEPSS 1.72%

Last modified

CVE-2017-9852 is a vulnerability of currently unknown severity. An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. EPSS estimates a 1.72% chance of exploitation in the next 30 days.

Description

An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer passwords are expected to be default or similar across installations installed by the same company (but are sometimes changed). Hidden user accounts have (at least in some cases, though more research is required to test this for all hidden user accounts) a fixed password for all devices; it can never be changed by a user. Other vulnerabilities exist that allow an attacker to get the passwords of these hidden user accounts. NOTE: the vendor reports that it has no influence on the allocation of passwords, and that global hardcoded master passwords do not exist. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Metrics

EPSS Probability
1.72%

74.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SmaSunny Boy 3600 FirmwareAll versions
SmaSunny Boy 5000 FirmwareAll versions
SmaSunny Tripower Core1 FirmwareAll versions
SmaSunny Tripower 15000tl FirmwareAll versions
SmaSunny Tripower 20000tl FirmwareAll versions
SmaSunny Tripower 25000tl FirmwareAll versions
SmaSunny Tripower 5000tl FirmwareAll versions
SmaSunny Tripower 12000tl FirmwareAll versions
SmaSunny Tripower 60 FirmwareAll versions
SmaSunny Boy 3000tl FirmwareAll versions
SmaSunny Boy 3600tl FirmwareAll versions
SmaSunny Boy 4000tl FirmwareAll versions
SmaSunny Boy 5000tl FirmwareAll versions
SmaSunny Boy 1.5 FirmwareAll versions
SmaSunny Boy 2.5 FirmwareAll versions
SmaSunny Boy 3.0 FirmwareAll versions
SmaSunny Boy 3.6 FirmwareAll versions
SmaSunny Boy 4.0 FirmwareAll versions
SmaSunny Boy 5.0 FirmwareAll versions
SmaSunny Central 2200 FirmwareAll versions
SmaSunny Central 1000cp Xt FirmwareAll versions
SmaSunny Central 800cp Xt FirmwareAll versions
SmaSunny Central 850cp Xt FirmwareAll versions
SmaSunny Central 900cp Xt FirmwareAll versions
SmaSunny Central 500cp Xt FirmwareAll versions
SmaSunny Central 630cp Xt FirmwareAll versions
SmaSunny Central 720cp Xt FirmwareAll versions
SmaSunny Central 760cp Xt FirmwareAll versions
SmaSunny Central Storage 500 FirmwareAll versions
SmaSunny Central Storage 630 FirmwareAll versions
SmaSunny Central Storage 720 FirmwareAll versions
SmaSunny Central Storage 760 FirmwareAll versions
SmaSunny Central Storage 800 FirmwareAll versions
SmaSunny Central Storage 850 FirmwareAll versions
SmaSunny Central Storage 900 FirmwareAll versions
SmaSunny Central Storage 1000 FirmwareAll versions
SmaSunny Central Storage 2200 FirmwareAll versions
SmaSunny Central Storage 2500-Ev FirmwareAll versions
SmaSunny Boy Storage 2.5 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-9852?
An Incorrect Password Management issue was discovered in SMA Solar Technology products. Default passwords exist that are rarely changed. User passwords will almost always be default. Installer passwords are expected to be default or similar across installations installed by the same company (but are sometimes changed). Hidden user accounts have (at least in some cases, though more research is required to test this for all hidden user accounts) a fixed password for all devices; it can never be changed by a user. Other vulnerabilities exist that allow an attacker to get the passwords of these hidden user accounts. NOTE: the vendor reports that it has no influence on the allocation of passwords, and that global hardcoded master passwords do not exist. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
How severe is CVE-2017-9852?
Severity scoring for CVE-2017-9852 is pending analysis. The EPSS model estimates a 1.72% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9852?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-9852?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST