ZeroHour

CVE-2017-9856

CVSS 3.1
3.4 low
EPSS
<1%p50
Published
()
Modified
Description

An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are "encrypted" using a very simple encryption algorithm. This enables an attacker to find the plaintext passwords and authenticate to the device. NOTE: the vendor reports that only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Vendors
sma
Products
sunny boy 3600 firmware, sunny boy 5000 firmware, sunny tripower core1 firmware, sunny tripower 15000tl firmware, sunny tripower 20000tl firmware, sunny tripower 25000tl firmware, sunny tripower 5000tl firmware, sunny tripower 12000tl firmware, sunny tripower 60 firmware, sunny boy 3000tl firmware, sunny boy 3600tl firmware, sunny boy 4000tl firmware
Weakness
CWE-256
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.