CVE-2016-5782

An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for voltage monitoring and network configuration. The PHP code does not properly validate information that is sent in the POST request.
References
Link Resource
http://www.securityfocus.com/bid/94698 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/94782 VDB Entry Third Party Advisory
https://ics-cert.us-cert.gov/advisories/ICSA-16-231-01-0 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:locusenergy:lgate_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:locusenergy:lgate_100:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_101:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_120:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_320:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_50:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-13 21:59

Updated : 2024-02-28 15:44


NVD link : CVE-2016-5782

Mitre link : CVE-2016-5782

CVE.ORG link : CVE-2016-5782


JSON object : View

Products Affected

locusenergy

  • lgate_firmware
  • lgate_120
  • lgate_50
  • lgate_320
  • lgate_100
  • lgate_101
CWE
CWE-20

Improper Input Validation