PT-2017-19224 · Sma Solar Technology · Sunny Boy Tlst-21+2

Willem Westerhof

·

Published

2017-08-05

·

Updated

2024-08-05

·

CVE-2017-9858

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SMA Solar Technology products, specifically Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10, TL-30
Description An issue in SMA Solar Technology products allows determination of active and inactive user accounts by sending crafted packets to an inverter and observing the response. This information can aid in further attacks, such as brute force attacks, by identifying existing user accounts.
Recommendations For Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10, TL-30, consider implementing additional security measures to prevent brute force attacks, such as account lockout policies or rate limiting on login attempts, until a more comprehensive solution is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2017-9858

Affected Products

Sunny Boy Tlst-21
Sunny Tripower Tl-10
Sunny Tripower Tl-30