CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
64.7%
An issue was discovered in SMA Solar Technology products. Sniffed passwords from SMAdata2+ communication can be decrypted very easily. The passwords are “encrypted” using a very simple encryption algorithm. This enables an attacker to find the plaintext passwords and authenticate to the device. NOTE: the vendor reports that only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
Vendor | Product | Version | CPE |
---|---|---|---|
sma | sunny_boy_3600_firmware | - | cpe:2.3:o:sma:sunny_boy_3600_firmware:-:*:*:*:*:*:*:* |
sma | sunny_boy_3600 | - | cpe:2.3:h:sma:sunny_boy_3600:-:*:*:*:*:*:*:* |
sma | sunny_boy_5000 | - | cpe:2.3:h:sma:sunny_boy_5000:-:*:*:*:*:*:*:* |
sma | sunny_boy_5000_firmware | - | cpe:2.3:o:sma:sunny_boy_5000_firmware:-:*:*:*:*:*:*:* |
sma | sunny_tripower_core1 | - | cpe:2.3:h:sma:sunny_tripower_core1:-:*:*:*:*:*:*:* |
sma | sunny_tripower_core1_firmware | - | cpe:2.3:o:sma:sunny_tripower_core1_firmware:-:*:*:*:*:*:*:* |
sma | sunny_tripower_15000tl | - | cpe:2.3:h:sma:sunny_tripower_15000tl:-:*:*:*:*:*:*:* |
sma | sunny_tripower_15000tl_firmware | - | cpe:2.3:o:sma:sunny_tripower_15000tl_firmware:-:*:*:*:*:*:*:* |
sma | sunny_tripower_20000tl_firmware | - | cpe:2.3:o:sma:sunny_tripower_20000tl_firmware:-:*:*:*:*:*:*:* |
sma | sunny_tripower_20000tl | - | cpe:2.3:h:sma:sunny_tripower_20000tl:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
AI Score
Confidence
High
EPSS
Percentile
64.7%