PT-2017-19230 · Sma Solar Technology · Sunny Boy Tlst-21+2

·

CVE-2017-9864

·

Published

2017-08-05

·

Updated

2024-08-05

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SMA Solar Technology products, specifically Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10, TL-30
Description An issue allows an attacker to change the plant time without authentication, potentially affecting system time and making timestamps for data analysis unreliable. However, the vendor reports that this issue is largely irrelevant as it only affects log-entry timestamps and the plant time would later be reset via NTP.
Recommendations For Sunny Boy TLST-21, TL-21, and Sunny Tripower TL-10, TL-30, consider restricting access to time-setting functionality until a patch is available. As a temporary workaround, ensure NTP is properly configured to reset the plant time and minimize the impact of the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-9864

Affected Products

Sunny Boy Tlst-21
Sunny Tripower Tl-10
Sunny Tripower Tl-30