{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]},{"organization":"INCIBE","summary":"reporting","urls":["https://www.incibe.es"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"A security researcher discovered that in the affected products a clickjacking vulnerability in the web frontend exists. An attacker could lure the user to click on a malicious website which seems to be the WebUI of the affected product. The affected products are out of support (End-of-Life 2015-12-31).","title":"Summary"},{"category":"description","text":"A user can be tricked into unwanted actions on other systems while he expects to click on the Webbox WebUI.","title":"Impact"},{"category":"description","text":"If you can not replace your Webbox by a suitable up-to-date product then isolate the affected network segment by blocking all incoming network traffic. Especially never configure your network to allow a port forwarding to SMA Webbox.","title":"Mitigation"},{"category":"description","text":"Replace out-of-support Sunny Webbox / Sunny Webbox with Bluetooth to a suitable up-to-date product. Please note technical information on the switchover to be found at https://www.sma-sunny.com/en/how-to-replace-old-data-logger/","title":"Remediation"}],"publisher":{"category":"vendor","contact_details":"information-security@sma.de","name":"SMA Solar Technology AG","namespace":"https://sma.de"},"references":[{"category":"external","summary":"SMA PSIRT","url":"https://www.sma.de/en/cybersecurity/product-security"},{"category":"external","summary":"CERT@VDE Security Advisories for SMA","url":"https://certvde.com/en/advisories/vendor/sma/"},{"category":"self","summary":"VDE-2024-075: SMA: Sunny Webbox clickjacking vulnerability - HTML","url":"https://certvde.com/en/advisories/VDE-2024-075"},{"category":"self","summary":"VDE-2024-075: SMA: Sunny Webbox clickjacking vulnerability - CSAF","url":"https://sma.csaf-tp.certvde.com/.well-known/csaf/white/2025/vde-2024-075.json"}],"title":"SMA: Sunny Webbox clickjacking vulnerability","tracking":{"aliases":["VDE-2024-075"],"current_release_date":"2025-06-17T06:00:00.000Z","generator":{"date":"2025-06-17T05:54:59.215Z","engine":{"name":"Secvisogram","version":"2.5.26"}},"id":"VDE-2024-075","initial_release_date":"2025-01-27T13:00:00.000Z","revision_history":[{"date":"2025-01-20T11:00:00.000Z","number":"1.0.0","summary":"Initial revision."},{"date":"2025-02-12T16:48:47.000Z","number":"2.0.0","summary":"Fix: corrected self-reference"},{"date":"2025-06-17T06:00:00.000Z","number":"2.0.1","summary":"fixed typo: Got 'vers:all/* ', expected 'vers:all/*', switched to semver versioning scheme"}],"status":"final","version":"2.0.1"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SMA Sunny Webbox","product":{"name":"SMA Sunny Webbox","product_id":"CSAFPID-11900"}},{"category":"product_name","name":"SMA Sunny Webbox with Bluetooth","product":{"name":"SMA Sunny Webbox with Bluetooth","product_id":"CSAFPID-11901"}}],"category":"product_family","name":"Sunny Webbox"}],"category":"product_family","name":"Hardware"},{"branches":[{"category":"product_version_range","name":"vers:all/* ","product":{"name":"SMA Sunny Webbox Firmware all","product_id":"CSAFPID-21900"}}],"category":"product_family","name":"Firmware"}],"category":"vendor","name":"SMA Solar Technology AG"}],"product_groups":[{"group_id":"CSAFGID-0001","product_ids":["CSAFPID-11900","CSAFPID-11901"],"summary":"Affected products, End of Life"}],"relationships":[{"category":"installed_on","full_product_name":{"name":"All firmware installed on  SMA Sunny Webbox","product_id":"CSAFPID-32900"},"product_reference":"CSAFPID-21900","relates_to_product_reference":"CSAFPID-11900"},{"category":"installed_on","full_product_name":{"name":"All firmware installed on SMA Sunny Webbox with Bluetooth","product_id":"CSAFPID-32901"},"product_reference":"CSAFPID-21900","relates_to_product_reference":"CSAFPID-11901"}]},"vulnerabilities":[{"cve":"CVE-2024-1890","cwe":{"id":"CWE-1021","name":"Improper Restriction of Rendered UI Layers or Frames"},"notes":[{"audience":"all","category":"description","text":"Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-11900","CSAFPID-11901"]},"release_date":"2024-02-26T11:00:00.000Z","remediations":[{"category":"mitigation","date":"2025-01-20T11:00:00.000Z","details":"Replace out-of-support Sunny Webbox / Sunny Webbox with Bluetooth to a suitable up-to-date product. Please note technical information on the switchover to be found at https://www.sma-sunny.com/en/how-to-replace-old-data-logger/","group_ids":["CSAFGID-0001"]}],"scores":[{"cvss_v3":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","environmentalScore":6.4,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","temporalScore":6.4,"temporalSeverity":"MEDIUM","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:L","version":"3.1"},"products":["CSAFPID-11900","CSAFPID-11901"]}],"title":"CVE-2024-1890"}]}