Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CISA advisory ICSA-26-160-02 discloses two vulnerabilities in Siemens KACO Blueplanet solar inverters affecting 30+ models deployed globally in energy sector critical infrastructure. The more severe flaw (CVE-2025-40946, CVSS 8.3) allows any network-accessible attacker to derive valid Technical Service credentials directly from a device serial number, bypassing authentication entirely. The vendor has confirmed no remediation is available for the majority of affected devices, leaving organizations dependent on compensating controls to protect operational technology assets with no patch remediation path.

Author

Tech Jacks Solutions