Share: Email | Twitter

ID

VDE-2024-075

Published

2025-01-27 14:00 (CET)

Last update

2025-01-27 09:52 (CET)

Vendor(s)

SMA Solar Technology AG

Product(s)

Article No° Product Name Affected Version(s)
SMA Sunny Webbox all
SMA Sunny Webbox with Bluetooth all

Summary

A security researcher discovered that in the affected products a clickjacking vulnerability in the web frontend exists. An attacker could lure the user to click on a malicious website which seems to be the WebUI of the affected product. The affected products are out of support (End-of-Life 2015-12-31).


Last Update:

27. Januar 2025 09:13

Weakness

Improper Restriction of Rendered UI Layers or Frames  (CWE-1021) 

Summary

Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.


Impact

A user can be tricked into unwanted actions on other systems while he expects to click on the Webbox WebUI.

Solution

Mitigation

If you can not replace your Webbox by a suitable up-to-date product then isolate the affected network segment by blocking all incoming network traffic. Especially never configure your network to allow a port forwarding to SMA Webbox.

Remediation

Replace out-of-support Sunny Webbox / Sunny Webbox with Bluetooth to a suitable up-to-date product. Please note technical information on the switchover to be found at sma-sunny.com/en/how-to-replace-old-data-logger/

Reported by

SMA Solar Technology AG thanks the following parties for their efforts: