CVE-2017-9857

UnknownEPSS 0.69%

Last modified

CVE-2017-9857 is a vulnerability of currently unknown severity. An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay attacks. EPSS estimates a 0.69% chance of exploitation in the next 30 days.

Description

An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay attacks. Any setting change, authentication packet, scouting packet, etc. can be replayed, injected, or used for a man in the middle session. All functionalities available in Sunny Explorer can effectively be done from anywhere within the network as long as an attacker gets the packet setup correctly. This includes the authentication process for all (including hidden) access levels and the changing of settings in accordance with the gained access rights. Furthermore, because the SMAdata2+ communication channel is unencrypted, an attacker capable of understanding the protocol can eavesdrop on communications. NOTE: the vendor's position is that authentication with encryption is not required on an isolated subnetwork. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Metrics

EPSS Probability
0.69%

48.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SmaSunny Boy 3600 FirmwareAll versions
SmaSunny Boy 5000 FirmwareAll versions
SmaSunny Tripower Core1 FirmwareAll versions
SmaSunny Tripower 15000tl FirmwareAll versions
SmaSunny Tripower 20000tl FirmwareAll versions
SmaSunny Tripower 25000tl FirmwareAll versions
SmaSunny Tripower 5000tl FirmwareAll versions
SmaSunny Tripower 12000tl FirmwareAll versions
SmaSunny Tripower 60 FirmwareAll versions
SmaSunny Boy 3000tl FirmwareAll versions
SmaSunny Boy 3600tl FirmwareAll versions
SmaSunny Boy 4000tl FirmwareAll versions
SmaSunny Boy 5000tl FirmwareAll versions
SmaSunny Boy 1.5 FirmwareAll versions
SmaSunny Boy 2.5 FirmwareAll versions
SmaSunny Boy 3.0 FirmwareAll versions
SmaSunny Boy 3.6 FirmwareAll versions
SmaSunny Boy 4.0 FirmwareAll versions
SmaSunny Boy 5.0 FirmwareAll versions
SmaSunny Central 2200 FirmwareAll versions
SmaSunny Central 1000cp Xt FirmwareAll versions
SmaSunny Central 800cp Xt FirmwareAll versions
SmaSunny Central 850cp Xt FirmwareAll versions
SmaSunny Central 900cp Xt FirmwareAll versions
SmaSunny Central 500cp Xt FirmwareAll versions
SmaSunny Central 630cp Xt FirmwareAll versions
SmaSunny Central 720cp Xt FirmwareAll versions
SmaSunny Central 760cp Xt FirmwareAll versions
SmaSunny Central Storage 500 FirmwareAll versions
SmaSunny Central Storage 630 FirmwareAll versions
SmaSunny Central Storage 720 FirmwareAll versions
SmaSunny Central Storage 760 FirmwareAll versions
SmaSunny Central Storage 800 FirmwareAll versions
SmaSunny Central Storage 850 FirmwareAll versions
SmaSunny Central Storage 900 FirmwareAll versions
SmaSunny Central Storage 1000 FirmwareAll versions
SmaSunny Central Storage 2200 FirmwareAll versions
SmaSunny Central Storage 2500-Ev FirmwareAll versions
SmaSunny Boy Storage 2.5 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-9857?
An issue was discovered in SMA Solar Technology products. The SMAdata2+ communication protocol does not properly use authentication with encryption: it is vulnerable to man in the middle, packet injection, and replay attacks. Any setting change, authentication packet, scouting packet, etc. can be replayed, injected, or used for a man in the middle session. All functionalities available in Sunny Explorer can effectively be done from anywhere within the network as long as an attacker gets the packet setup correctly. This includes the authentication process for all (including hidden) access levels and the changing of settings in accordance with the gained access rights. Furthermore, because the SMAdata2+ communication channel is unencrypted, an attacker capable of understanding the protocol can eavesdrop on communications. NOTE: the vendor's position is that authentication with encryption is not required on an isolated subnetwork. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
How severe is CVE-2017-9857?
Severity scoring for CVE-2017-9857 is pending analysis. The EPSS model estimates a 0.69% probability of exploitation in the next 30 days.
How do I fix CVE-2017-9857?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-9857?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST