CVE-2016-5782

An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for voltage monitoring and network configuration. The PHP code does not properly validate information that is sent in the POST request.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-16-231-01-0 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/94782 VDB Entry Third Party Advisory
http://www.securityfocus.com/bid/94698 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:locusenergy:lgate_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:locusenergy:lgate_100:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_120:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_320:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_50:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_101:-:*:*:*:*:*:*:*

Information

Published : 2017-02-13 13:59

Updated : 2017-03-14 12:17


NVD link : CVE-2016-5782

Mitre link : CVE-2016-5782


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

locusenergy

  • lgate_50
  • lgate_101
  • lgate_120
  • lgate_firmware
  • lgate_320
  • lgate_100