PT-2017-19228 · Sma Solar Technology · Sunny Boy Tlst-21+3

·

CVE-2017-9862

·

Publicado

2017-08-05

·

Atualizado

2024-08-05

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SMA Solar Technology products, specifically Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30
Description An issue in SMA Solar Technology products allows information disclosure when a user signs into Sunny Explorer with an incorrect password. This enables the creation of a debug report, which can disclose application information. An attacker can exploit this to create and save a .txt file with arbitrary contents, potentially writing to normally inaccessible locations on the local system. The vendor notes that the information in the debug report is of marginal significance.
Recommendations For Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30, consider restricting access to the debug report feature until a fix is available. As a temporary workaround, limit the ability to create and save .txt files through the Sunny Explorer application to minimize the risk of exploitation.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9862

Produtos afetados

Sunny Boy Tlst-21
Sunny Explorer
Sunny Tripower Tl-10
Sunny Tripower Tl-30