PT-2017-19228 · Sma Solar Technology · Sunny Boy Tlst-21+3
Willem Westerhof
·
Published
2017-08-05
·
Updated
2024-08-05
·
CVE-2017-9862
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SMA Solar Technology products, specifically Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30
Description
An issue in SMA Solar Technology products allows information disclosure when a user signs into Sunny Explorer with an incorrect password. This enables the creation of a debug report, which can disclose application information. An attacker can exploit this to create and save a .txt file with arbitrary contents, potentially writing to normally inaccessible locations on the local system. The vendor notes that the information in the debug report is of marginal significance.
Recommendations
For Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30, consider restricting access to the debug report feature until a fix is available. As a temporary workaround, limit the ability to create and save .txt files through the Sunny Explorer application to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sunny Boy Tlst-21
Sunny Explorer
Sunny Tripower Tl-10
Sunny Tripower Tl-30