PT-2017-19224 · Sma Solar Technology · Sunny Boy Tlst-21+2
Willem Westerhof
·
Published
2017-08-05
·
Updated
2024-08-05
·
CVE-2017-9858
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SMA Solar Technology products, specifically Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10, TL-30
Description
An issue in SMA Solar Technology products allows determination of active and inactive user accounts by sending crafted packets to an inverter and observing the response. This information can aid in further attacks, such as brute force attacks, by identifying existing user accounts.
Recommendations
For Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10, TL-30, consider implementing additional security measures to prevent brute force attacks, such as account lockout policies or rate limiting on login attempts, until a more comprehensive solution is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sunny Boy Tlst-21
Sunny Tripower Tl-10
Sunny Tripower Tl-30