news.mlab.sh
Back to the feed
vulnerability

Siemens KACO Blueplanet Inverters

High
Summary

This advisory from CISA details vulnerabilities within Siemens KACO Blueplanet Inverters, a series of industrial inverters used in energy systems. The vulnerabilities, specifically a CRC16-based algorithm for generating technical service credentials based on the device serial number, could allow unauthorized access and credential misuse. KACO new energy GmbH has released updated versions and recommends immediate patching to mitigate this risk.

Siemens KACO Blueplanet Inverters are a widely deployed product in the energy sector, and this advisory highlights a critical security concern. The vulnerability stems from a flaw in the device’s authentication process, where an attacker could potentially derive credentials by analyzing the device’s serial number. This allows for unauthorized access to the inverters’ control systems. KACO new energy GmbH has responded by releasing updated versions of the affected products, urging users to promptly apply these fixes. The company also recommends implementing countermeasures where immediate fixes aren't available. The affected product range is extensive, covering multiple Blueplanet inverter models across various generations and configurations.

Read the full article at CISA Advisories