ZeroHour

CVE-2017-5165

CVSS 3.0
7.6 high
EPSS
<1%p50
Published
()
Modified
Description

An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.

Vendors
binom3
Products
universal multifunctional electric power quality meter firmware
Weakness
CWE-352
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

In the news

No ingested article mentions this CVE yet.