
New Video Highlights Cybersecurity Risks in Solar Energy Systems
In this video, Daniel and Franchesca from Scout Technologies present their research on vulnerabilities and exploits discovered in certain solar energy systems and devices. Their work focuses on remote management systems for solar inverters, which are essential components for converting solar energy into usable electricity. These systems are often connected to the Internet to enable remote management and monitoring, making them vulnerable to cyberattacks.
The researchers explain that solar energy is expanding rapidly and could become the primary source of electricity by mid-century. However, the cybersecurity of these systems is not always sufficiently analyzed. Solar inverters, which convert direct current (DC) to alternating current (AC), are often connected to communication dongles to enable remote management via mobile or web applications. These dongles can sometimes be directly exposed to the Internet, increasing the risk of cyberattacks.
Daniel and Franchesca examined the top 10 global suppliers of solar inverters and discovered vulnerabilities in three of them: SMA, Growatt, and Sungrow. Among the identified vulnerabilities are access control issues, Insecure Direct Object References (IDOR) flaws, cross-site scripting (XSS), unrestricted file uploads, unverified certificates, and hardcoded credentials. Some of these vulnerabilities allowed remote code execution and account takeovers.
For SMA, an unrestricted file upload vulnerability enabled remote code execution on their cloud platform. At Growatt, the researchers found 36 vulnerabilities, mainly IDOR, which allowed account takeovers and attack scenarios such as controlling connected smart devices. Finally, at Sungrow, hardcoded credentials for MQTT communications and buffer overflows allowed the takeover of communication dongles and potentially the inverters themselves.
The practical implications of these findings are significant. The ability to control a large number of inverters could allow attackers to destabilize the power grid by altering energy production. Previous studies have shown that controlling less than 2% of inverters in Europe could cause significant disruptions. Additionally, financial attacks could be carried out by manipulating the security parameters of inverters to obtain financial gains.
The researchers emphasize the importance of collaboration between users, installers, utilities, regulators, and manufacturers to secure these systems. They recommend rigorous cybersecurity practices, such as regular software updates, the use of strong passwords, and limiting the exposure of devices to the Internet. Manufacturers should also adopt secure development cycles to integrate security features from the design stage.
In conclusion, this video highlights the growing risks associated with the cybersecurity of solar energy systems and the importance of taking proactive measures to secure them. The discovered vulnerabilities show that coordinated attacks could have significant impacts on the power grid, underscoring the need for increased vigilance and collaboration among all stakeholders.