CVE-2017-9855

CRITICALCVSS 9.8/10EPSS 1.58%

Last modified

CVE-2017-9855 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. EPSS estimates a 1.58% chance of exploitation in the next 30 days.

Description

An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can be used on any SMA inverter. Any such code, when combined with the installer account, allows changing very sensitive parameters. NOTE: the vendor reports that Grid Guard is not an authentication feature; it is only a tracing feature. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
1.58%

72.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SmaSunny Boy 3600 FirmwareAll versions
SmaSunny Boy 5000 FirmwareAll versions
SmaSunny Tripower Core1 FirmwareAll versions
SmaSunny Tripower 15000tl FirmwareAll versions
SmaSunny Tripower 20000tl FirmwareAll versions
SmaSunny Tripower 25000tl FirmwareAll versions
SmaSunny Tripower 5000tl FirmwareAll versions
SmaSunny Tripower 12000tl FirmwareAll versions
SmaSunny Tripower 60 FirmwareAll versions
SmaSunny Boy 3000tl FirmwareAll versions
SmaSunny Boy 3600tl FirmwareAll versions
SmaSunny Boy 4000tl FirmwareAll versions
SmaSunny Boy 5000tl FirmwareAll versions
SmaSunny Boy 1.5 FirmwareAll versions
SmaSunny Boy 2.5 FirmwareAll versions
SmaSunny Boy 3.0 FirmwareAll versions
SmaSunny Boy 3.6 FirmwareAll versions
SmaSunny Boy 4.0 FirmwareAll versions
SmaSunny Boy 5.0 FirmwareAll versions
SmaSunny Central 2200 FirmwareAll versions
SmaSunny Central 1000cp Xt FirmwareAll versions
SmaSunny Central 800cp Xt FirmwareAll versions
SmaSunny Central 850cp Xt FirmwareAll versions
SmaSunny Central 900cp Xt FirmwareAll versions
SmaSunny Central 500cp Xt FirmwareAll versions
SmaSunny Central 630cp Xt FirmwareAll versions
SmaSunny Central 720cp Xt FirmwareAll versions
SmaSunny Central 760cp Xt FirmwareAll versions
SmaSunny Central Storage 500 FirmwareAll versions
SmaSunny Central Storage 630 FirmwareAll versions
SmaSunny Central Storage 720 FirmwareAll versions
SmaSunny Central Storage 760 FirmwareAll versions
SmaSunny Central Storage 800 FirmwareAll versions
SmaSunny Central Storage 850 FirmwareAll versions
SmaSunny Central Storage 900 FirmwareAll versions
SmaSunny Central Storage 1000 FirmwareAll versions
SmaSunny Central Storage 2200 FirmwareAll versions
SmaSunny Central Storage 2500-Ev FirmwareAll versions
SmaSunny Boy Storage 2.5 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-9855?
An issue was discovered in SMA Solar Technology products. A secondary authentication system is available for Installers called the Grid Guard system. This system uses predictable codes, and a single Grid Guard code can be used on any SMA inverter. Any such code, when combined with the installer account, allows changing very sensitive parameters. NOTE: the vendor reports that Grid Guard is not an authentication feature; it is only a tracing feature. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
How severe is CVE-2017-9855?
CVE-2017-9855 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 1.58% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9855?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-9855?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST