ETFOptimize | High-performance ETF-based Investment Strategies

Quantitative strategies, Wall Street-caliber research, and insightful market analysis since 1998.


ETFOptimize | HOME
Close Window

Forescout Vedere Labs Uncovers Severe Systemic Security Risks in Global Solar Power Infrastructure

Research identifies 46 new solar power system vulnerabilities, posing a risk to grid stability and availability and potentially allowing attackers to seize control of solar inverters

Forescout Technologies Inc., a global cybersecurity leader, today published its “SUN:DOWN – Destabilizing the Grid via Orchestrated Exploitation of Solar Power Systems” research report. Forescout Research – Vedere Labs discovered 46 new vulnerabilities across three of the world’s 10 leading solar inverter vendors. Additionally, Vedere Labs found that 80% of vulnerabilities in solar power systems disclosed in the last three years were classified as high or critical severity. These findings reveal severe systemic security weaknesses in the solar ecosystem that could impact power grid stability, utility operations, and consumer data privacy.

“The collective impact of residential solar systems on grid reliability is too significant to ignore – hospitals could lose access to critical equipment, families could go without heat in the winter or AC in a heatwave, and businesses could shut down,” said Barry Mainz, Forescout CEO. “Threat actors increasingly target critical infrastructure, making it essential to take them seriously and secure solar inverter systems before vulnerabilities lead to real-world disruptions.”

Forescout research key findings include:

  • 46 new vulnerabilities across three of the world’s top 10 solar inverter vendors worldwide: Sungrow, Growatt, and SMA. Some of these vulnerabilities enable attackers to tamper with inverter settings and compromise user privacy.
  • Consistent, severe cybersecurity gaps: On average, 10 vulnerabilities on solar power systems have been disclosed each year over the past three years. Of the 93 previously disclosed vulnerabilities, 80% were classified as high or critical severity and 30% had the highest possible CVSS scores (9.8–10), meaning the attacker could take full control of an affected system.
  • Growing geopolitical concerns in solar supply chains: Over half of solar inverter manufacturers (53%) and storage system providers (58%) are based in China. Twenty percent of the monitoring system manufacturers are also from China, raising concerns over the dominance of foreign-made solar power components.

Potential attack scenarios and impact:

Attackers could exploit these vulnerabilities to take control of solar inverter systems in several ways. Growatt inverters were susceptible to cloud-based takeover, allowing unauthorized access and control of a user’s resources, solar plants, and devices. Sungrow inverters could be hijacked by harvesting communication dongle serial numbers through various insecure direct object references (IDORs), using hard-coded credentials found on the device and publishing messages that lead to remote code execution, and full takeover of the inverter.

By exploiting these weaknesses, cybercriminals could manipulate power generation at scale and trigger coordinated load-changing attacks to destabilize the grid—potentially leading to emergency power measures, grid disconnections, or even blackouts.

Following responsible disclosure, all vendors have patched the reported issues.

“Solar power systems are rapidly becoming essential elements of power grids throughout the world, but persistent security flaws threaten both grid stability and national security,” said Daniel dos Santos, Head of Research at Forescout Research – Vedere Labs. “To mitigate these risks, owners of commercial installations should enforce strict security requirements when procuring solar equipment, conduct regular risk assessments, ensure full network visibility into these devices and segment them into sub-networks with continuous monitoring.”

To learn more about the vulnerabilities, realistic attack scenarios and impact, and mitigation advice for owners of smart inverters, utilities, device manufacturers, and regulators, download the full research report, review the summary blog, and join the webinar.

About Forescout

The Forescout cybersecurity platform provides complete asset intelligence and control across IT, OT, IoT, and IoMT environments. For more than 20 years, Fortune 100 organizations, government agencies, and large enterprises have trusted Forescout as their foundation to manage cyber risk, ensure compliance, and mitigate threats. With seamless context sharing and workflow orchestration across more than 100 full-featured security and IT product integrations, Forescout makes every cybersecurity investment more effective.

Forescout Research – Vedere Labs is the industry leader in device intelligence, curating unique and proprietary threat intelligence that powers Forescout’s platform.

Contacts

Recent Quotes

View More
Symbol Price Change (%)
AMZN  210.00
+2.08 (1.00%)
AAPL  264.18
-8.77 (-3.21%)
AMD  213.84
+0.00 (0.00%)
BAC  49.83
-2.47 (-4.72%)
GOOG  311.43
+4.28 (1.39%)
META  648.18
-8.83 (-1.34%)
MSFT  389.00
+0.00 (0.00%)
NVDA  177.19
-7.70 (-4.16%)
ORCL  145.40
-4.91 (-3.27%)
TSLA  402.51
-6.07 (-1.49%)
Stock Quote API & Stock News API supplied by www.cloudquote.io
Quotes delayed at least 20 minutes.
By accessing this page, you agree to the Privacy Policy and Terms Of Service.


 

IntelligentValue Home
Close Window

DISCLAIMER

All content herein is issued solely for informational purposes and is not to be construed as an offer to sell or the solicitation of an offer to buy, nor should it be interpreted as a recommendation to buy, hold or sell (short or otherwise) any security.  All opinions, analyses, and information included herein are based on sources believed to be reliable, but no representation or warranty of any kind, expressed or implied, is made including but not limited to any representation or warranty concerning accuracy, completeness, correctness, timeliness or appropriateness. We undertake no obligation to update such opinions, analysis or information. You should independently verify all information contained on this website. Some information is based on analysis of past performance or hypothetical performance results, which have inherent limitations. We make no representation that any particular equity or strategy will or is likely to achieve profits or losses similar to those shown. Shareholders, employees, writers, contractors, and affiliates associated with ETFOptimize.com may have ownership positions in the securities that are mentioned. If you are not sure if ETFs, algorithmic investing, or a particular investment is right for you, you are urged to consult with a Registered Investment Advisor (RIA). Neither this website nor anyone associated with producing its content are Registered Investment Advisors, and no attempt is made herein to substitute for personalized, professional investment advice. Neither ETFOptimize.com, Global Alpha Investments, Inc., nor its employees, service providers, associates, or affiliates are responsible for any investment losses you may incur as a result of using the information provided herein. Remember that past investment returns may not be indicative of future returns.

Copyright © 1998-2017 ETFOptimize.com, a publication of Optimized Investments, Inc. All rights reserved.