HIGH · 8.6

CVE-2016-5782

An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for v...

Vulnerability Description

An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for voltage monitoring and network configuration. The PHP code does not properly validate information that is sent in the POST request.

CVSS Score

8.6

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
LocusenergyLgate Firmware-
LocusenergyLgate 100-
LocusenergyLgate 101-
LocusenergyLgate 120-
LocusenergyLgate 320-
LocusenergyLgate 50-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-5782?

CVE-2016-5782 is a vulnerability with a CVSS score of 8.6 (HIGH). An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for v...

How severe is CVE-2016-5782?

CVE-2016-5782 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-5782?

Check the references section above for vendor advisories and patch information. Affected products include: Locusenergy Lgate Firmware, Locusenergy Lgate 100, Locusenergy Lgate 101, Locusenergy Lgate 120, Locusenergy Lgate 320.