V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-9861
CVE
Critical

An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it i…

CVSS
9.8
Critical
EPSS
0.01
p69
Published
2017-01-01
Updated
2017-01-01
Description

An issue was discovered in SMA Solar Technology products. The SIP implementation does not properly use authentication with encryption: it is vulnerable to replay attacks, packet injection attacks, and man in the middle attacks. An attacker is able to successfully use SIP to communicate with the device from anywhere within the LAN. An attacker may use this to crash the device, stop it from communicating with the SMA servers, exploit known SIP vulnerabilities, or find sensitive information from the SIP communications. Furthermore, because the SIP communication channel is unencrypted, an attacker capable of understanding the protocol can eavesdrop on communications. For example, passwords can be extracted. NOTE: the vendor's position is that authentication with encryption is not required on an isolated subnetwork. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected

Tags · CWE
Pre-auth
CWE-74
CAPEC-3
CAPEC-6
CAPEC-7
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-13
CAPEC-14
CAPEC-24
CAPEC-28
CAPEC-34
CAPEC-42
CAPEC-43
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-51
CAPEC-52
CAPEC-53
CAPEC-64
CAPEC-67
CAPEC-71
CAPEC-72
CAPEC-76
CAPEC-78
CAPEC-79
CAPEC-80
CAPEC-83
CAPEC-84
CAPEC-101
CAPEC-105
CAPEC-108
CAPEC-120
CAPEC-135
CAPEC-250
CAPEC-267
CAPEC-273
Affected products
Sunny_boy_1.5_firmwareSunny_boy_2.5_firmwareSunny_boy_3.0_firmwareSunny_boy_3.6_firmwareSunny_boy_3000tl_firmwareSunny_boy_3600_firmwareSunny_boy_3600tl_firmwareSunny_boy_4.0_firmwareSunny_boy_4000tl_firmwareSunny_boy_5.0_firmwareSunny_boy_5000_firmwareSunny_boy_5000tl_firmwareSunny_boy_storage_2.5_firmwareSunny_central_1000cp_xt_firmwareSunny_central_2200_firmwareSunny_central_500cp_xt_firmwareSunny_central_630cp_xt_firmwareSunny_central_720cp_xt_firmwareSunny_central_760cp_xt_firmwareSunny_central_800cp_xt_firmware
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.014 · p69
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
sunny_boy_1.5_firmware*Tracked
sunny_boy_2.5_firmware*Tracked
sunny_boy_3.0_firmware*Tracked
sunny_boy_3.6_firmware*Tracked
sunny_boy_3000tl_firmware*Tracked
sunny_boy_3600_firmware*Tracked
sunny_boy_3600tl_firmware*Tracked
sunny_boy_4.0_firmware*Tracked
sunny_boy_4000tl_firmware*Tracked
sunny_boy_5.0_firmware*Tracked
sunny_boy_5000_firmware*Tracked
sunny_boy_5000tl_firmware*Tracked
sunny_boy_storage_2.5_firmware*Tracked
sunny_central_1000cp_xt_firmware*Tracked
sunny_central_2200_firmware*Tracked
sunny_central_500cp_xt_firmware*Tracked
sunny_central_630cp_xt_firmware*Tracked
sunny_central_720cp_xt_firmware*Tracked
sunny_central_760cp_xt_firmware*Tracked
sunny_central_800cp_xt_firmware*Tracked
Showing first 20 of 39
Source databases
CVE