CVE-2017-9857 describes a critical authentication and encryption vulnerability in the SMAdata2+ communication protocol used by specific SMA Solar Technology products, including Sunny Boy TLST-21, TL-21, Sunny Tripower TL-10, and TL-30. This flaw allows for man-in-the-middle, packet injection, and replay attacks due to the lack of proper authentication and encryption, enabling attackers to gain full control over affected devices, including changing settings and accessing hidden functionalities. With a CVSS score of 8.1 (HIGH), this vulnerability poses a significant risk of high confidentiality, integrity, and availability impacts, despite requiring high attack complexity. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage, highlighting its potential for severe consequences, such as disrupting power grids.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sma:sunny_boy_3600_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sma:sunny_boy_5000_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sma:sunny_tripower_core1_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sma:sunny_tripower_15000tl_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:sma:sunny_tripower_20000tl_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.