ICSA-19-281-01
·
Published 2019-10-08
·
View on CISA ICS-CERT ↗
SMA Solar Technology AG Sunny WebBox
CVSS 9.6
CRITICAL
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to generate a denial-of-service condition, modify passwords, enable services, achieve man-in-the-middle, and modify input parameters associated with devices such as sensors.
CVEs (1)
Remediations
- This product is end-of-life and is no longer supported.
- SMA recommends deactivation of port forwarding as it is not required for monitoring PV systems via the SMA Sunny Portal. If direct access to a system from the Internet is necessary, SMA recommends using an encrypted virtual private network (VPN). On delivery, any saved default passwords should also be replaced with individual secure passwords, and unused ports on the system/router should be closed.
- SMA installers and administrators can answer specific questions about individual configuration of SMA devices. Basic information on this topic can also be found at: https://files.sma.de/dl/7680/CyberSecurity-TI-en-10.pdf
Affected Vendors
SMA Solar Technology AG
Affected Products (1)
SMA Solar Technology AG
·
Sunny WebBox Firmware
<= 1.6
Affected Sectors
Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more