CVE-2017-9856

LOWCVSS 3.4/10EPSS 0.66%

Last modified

CVE-2017-9856 is a low-severity vulnerability rated 3.4/10 on the CVSS scale. An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. EPSS estimates a 0.66% chance of exploitation in the next 30 days.

Description

An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption algorithm. This enables an attacker to find the plaintext passwords and authenticate to the device. NOTE: the vendor reports that only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Metrics

CVSS 3.1
3.4/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

EPSS Probability
0.66%

47.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SmaSunny Boy 3600 FirmwareAll versions
SmaSunny Boy 5000 FirmwareAll versions
SmaSunny Tripower Core1 FirmwareAll versions
SmaSunny Tripower 15000tl FirmwareAll versions
SmaSunny Tripower 20000tl FirmwareAll versions
SmaSunny Tripower 25000tl FirmwareAll versions
SmaSunny Tripower 5000tl FirmwareAll versions
SmaSunny Tripower 12000tl FirmwareAll versions
SmaSunny Tripower 60 FirmwareAll versions
SmaSunny Boy 3000tl FirmwareAll versions
SmaSunny Boy 3600tl FirmwareAll versions
SmaSunny Boy 4000tl FirmwareAll versions
SmaSunny Boy 5000tl FirmwareAll versions
SmaSunny Boy 1.5 FirmwareAll versions
SmaSunny Boy 2.5 FirmwareAll versions
SmaSunny Boy 3.0 FirmwareAll versions
SmaSunny Boy 3.6 FirmwareAll versions
SmaSunny Boy 4.0 FirmwareAll versions
SmaSunny Boy 5.0 FirmwareAll versions
SmaSunny Central 2200 FirmwareAll versions
SmaSunny Central 1000cp Xt FirmwareAll versions
SmaSunny Central 800cp Xt FirmwareAll versions
SmaSunny Central 850cp Xt FirmwareAll versions
SmaSunny Central 900cp Xt FirmwareAll versions
SmaSunny Central 500cp Xt FirmwareAll versions
SmaSunny Central 630cp Xt FirmwareAll versions
SmaSunny Central 720cp Xt FirmwareAll versions
SmaSunny Central 760cp Xt FirmwareAll versions
SmaSunny Central Storage 500 FirmwareAll versions
SmaSunny Central Storage 630 FirmwareAll versions
SmaSunny Central Storage 720 FirmwareAll versions
SmaSunny Central Storage 760 FirmwareAll versions
SmaSunny Central Storage 800 FirmwareAll versions
SmaSunny Central Storage 850 FirmwareAll versions
SmaSunny Central Storage 900 FirmwareAll versions
SmaSunny Central Storage 1000 FirmwareAll versions
SmaSunny Central Storage 2200 FirmwareAll versions
SmaSunny Central Storage 2500-Ev FirmwareAll versions
SmaSunny Boy Storage 2.5 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-9856?
An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption algorithm. This enables an attacker to find the plaintext passwords and authenticate to the device. NOTE: the vendor reports that only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
How severe is CVE-2017-9856?
CVE-2017-9856 has a CVSS score of 3.4/10 (LOW severity). The EPSS model estimates a 0.66% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9856?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-9856?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST