← Back to home
ICSA-19-281-01  ·  Published 2019-10-08  ·  View on CISA ICS-CERT ↗

SMA Solar Technology AG Sunny WebBox

CVSS 9.6 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to generate a denial-of-service condition, modify passwords, enable services, achieve man-in-the-middle, and modify input parameters associated with devices such as sensors.

CVEs (1)

Remediations

  • This product is end-of-life and is no longer supported.
  • SMA recommends deactivation of port forwarding as it is not required for monitoring PV systems via the SMA Sunny Portal. If direct access to a system from the Internet is necessary, SMA recommends using an encrypted virtual private network (VPN). On delivery, any saved default passwords should also be replaced with individual secure passwords, and unused ports on the system/router should be closed.
  • SMA installers and administrators can answer specific questions about individual configuration of SMA devices. Basic information on this topic can also be found at: https://files.sma.de/dl/7680/CyberSecurity-TI-en-10.pdf

Affected Vendors

SMA Solar Technology AG

Affected Products (1)

SMA Solar Technology AG · Sunny WebBox Firmware <= 1.6

Affected Sectors

Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more