Firmware Update Vulnerability in SMA Solar Technology Inverters
CVE-2017-9860

9.8CRITICAL

Key Information:

Vendor

Sma

Vendor
CVE Published:
5 August 2017

What is CVE-2017-9860?

A vulnerability has been identified in SMA Solar Technology products where an attacker can exploit the Sunny Explorer or SMAdata2+ network protocol to perform firmware updates without any form of authentication. This could allow malicious actors to inject custom firmware into affected inverters, such as Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10 and TL-30. If successful, an attacker could gain full control of the inverter, potentially accessing the local operating system and leveraging the device for various malicious activities including botnet creation and network infiltration. Though the vendor claims this threat is mitigated by a final integrity and compatibility check, attention to this vulnerability remains crucial for ensuring device security.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.