CVE-2016-5782

An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for voltage monitoring and network configuration. The PHP code does not properly validate information that is sent in the POST request.
References
Link Resource
http://www.securityfocus.com/bid/94698 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/94782 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-16-231-01-0 Third Party Advisory US Government Resource
http://www.securityfocus.com/bid/94698 Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/94782 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSA-16-231-01-0 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:locusenergy:lgate_firmware:-:*:*:*:*:*:*:*
OR cpe:2.3:h:locusenergy:lgate_100:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_101:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_120:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_320:-:*:*:*:*:*:*:*
cpe:2.3:h:locusenergy:lgate_50:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:55

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/94698 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/94698 - Third Party Advisory, VDB Entry
References () http://www.securityfocus.com/bid/94782 - VDB Entry, Third Party Advisory () http://www.securityfocus.com/bid/94782 - Third Party Advisory, VDB Entry
References () https://ics-cert.us-cert.gov/advisories/ICSA-16-231-01-0 - Third Party Advisory, US Government Resource () https://ics-cert.us-cert.gov/advisories/ICSA-16-231-01-0 - Third Party Advisory, US Government Resource

Information

Published : 2017-02-13 21:59

Updated : 2025-04-20 01:37


NVD link : CVE-2016-5782

Mitre link : CVE-2016-5782

CVE.ORG link : CVE-2016-5782


JSON object : View

Products Affected

locusenergy

  • lgate_firmware
  • lgate_120
  • lgate_101
  • lgate_100
  • lgate_50
  • lgate_320
CWE
CWE-20

Improper Input Validation