Vulnerability Details CVE-2017-5165
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. There is no CSRF Token generated per page and/or per (sensitive) function. Successful exploitation of this vulnerability can allow silent execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 25.5%
CVSS Severity
CVSS v3 Score 7.6
CVSS v2 Score 6.8
Products affected by CVE-2017-5165
-
cpe:2.3:h:binom3:universal_multifunctional_electric_power_quality_meter:-
-
cpe:2.3:o:binom3:universal_multifunctional_electric_power_quality_meter_firmware:-