KACO blueplanet 3.0 TL3-60.0 TL3
cpe:2.3:h:kaco-newenergy:xp100u:*:*:*:*:*:*:*, +1 more
- >= 6.1.4.0, < 6.1.4.9
A vulnerability exists in multiple KACO blueplanet inverter models, all versions, and certain models in versions prior to 6.1.4.9. This vulnerability allows an attacker to derive Technical Service credentials using a CRC16-based algorithm, exploiting the devices' serial numbers. The derived credentials could be misused to gain unauthorized access to the devices.
Exploitation of this vulnerability could lead to unauthorized access on the affected devices, allowing for potential misuse of the gained access rights.
KACO new energy GmbH has released updates for several affected products. For those products where no fix is currently available, KACO new energy GmbH recommends implementing appropriate security measures and following general security recommendations. Operators should validate any security updates before application and supervise the update process. Recommended security guidelines can be found on the Siemens Grid Security website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.