Back
CVE-2017-5145
CRITICAL
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving modified configuration.
Published: Feb 13, 2017
Modified: Jun 17, 2026
CWE-352
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| carlosgavazzi | vmu-c_em_firmware | - |
| carlosgavazzi | vmu-c_pv_firmware | - |
GitHub Security Advisory GHSA-6fhf-grw8-8h8h
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV...
References (4)
- http://www.securityfocus.com/bid/95411 Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-012-03 Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/95411 Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-012-03 Third Party Advisory, US Government Resource
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
1.25%
Top 34% most likely to be exploited
Threat Score
40.4 / 100
Data Sources
NVD
EPSS
GitHub