Researchers at cybersecurity firm Forescout have identified dozens of vulnerabilities in photovoltaic system products from Sungrow, Growatt and SMA, including weaknesses that could pose a serious threat to electrical grids.
See also: US Department of Energy: Collaboration with NVIDIA & Dell for the new supercomputer

Solar power is becoming increasingly important, especially in the United States and Europe. However, photovoltaic systems often have vulnerabilities that make them vulnerable to hacker attacks . Forescout has documented more than 90 vulnerabilities in such products in recent years, and its researchers recently identified 46 new weaknesses.
The security company analyzed products from the ten largest photovoltaic system suppliers and found serious security vulnerabilities in products from Sungrow, Growatt and SMA.
The basic components of a photovoltaic station are solar panels, which produce direct current (DC), and inverters, which convert direct current to alternating current (AC), so that the energy can be fed into the commercial grid or used locally.
In addition, modern photovoltaic stations include several cyberinfrastructure elements, such as a communication system that connects the system to the internet, a cloud service where data is sent for monitoring and control purposes, and a mobile application that allows the user to interact with the cloud service.
See also: Nova Scotia Power confirms Ransomware attack
In the case of SMA’s product, Forescout identified a vulnerability that allows an attacker to upload a malicious file, which enables the execution of arbitrary code on the cloud platform’s server. In Growatt’s products, researchers identified 30 vulnerabilities, which can be exploited for XSS attacks, obtaining sensitive information, taking full control of devices, and even causing physical damage to the system.

More than a dozen vulnerabilities were identified in Sungrow's photovoltaic products, including IDOR (Insecure Direct Object Reference) issues, which could lead to the leakage of sensitive information, as well as security holes that allow denial of service (DoS) attacks and remote execution of malicious code.
Some of the vulnerabilities identified by Forescout in these products could allow malicious actors to take control of a large number of inverters and use them to attack the power grid, even causing prolonged outages. In addition, these vulnerabilities could allow the extraction of personal user data, the exploitation of compromised devices to take over other devices on the same network, as well as creating financial impacts on network operators through energy price manipulation or ransomware.
Affected suppliers have been notified. SMA and Sungrow have patched all vulnerabilities and issued notices to inform their customers. In the cases of Sungrow and SMA, the US cybersecurity agency CISA also issued its own notices, noting that the affected products are used worldwide in the energy sector.
See also: Nova Scotia Power: Cyberattack led to data breach
A key conclusion that emerges from the above is that photovoltaic systems, despite their significant contribution to the energy transition and sustainability, are now a potential target in cyberspace. Their increasing interconnection with the internet and cloud services, for management and remote control purposes, makes them vulnerable to attacks that target not only individual security or personal data, but also the stability of entire energy networks.
Source: securityweek
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
