PatchSiren cyber security CVE debrief
CVE-2017-5164 Binom3 CVE debrief
CVE-2017-5164 is a cross-site scripting (XSS) vulnerability in BINOM3 Universal Multifunctional Electric Power Quality Meter firmware. The NVD record classifies it as CWE-79 and rates it CVSS 6.1 (Medium). Because the vector is network-based and user interaction is required, the main concern is browser-session compromise for users who access the affected interface.
- Vendor
- Binom3
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2017-02-07
- Advisory published
- 2017-01-31
- Advisory updated
- 2017-02-07
Who should care
Organizations that deploy or administer BINOM3 Universal Multifunctional Electric Power Quality Meter firmware, especially teams that manage the device’s web-facing administration or monitoring interface. Security teams should also care if users can access the interface from trusted browsers or internal networks, since the impact is on browser sessions.
Technical summary
The supplied NVD data describes an input-validation flaw where malicious client-supplied input is not properly verified by the server, enabling arbitrary script execution in another user’s browser session. NVD maps the issue to CWE-79 and provides a CVSS 3.0 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating remote reachability, no privileges required, user interaction, and potential cross-session impact.
Defensive priority
Medium. The vulnerability is externally reachable and can affect browser sessions, but it requires user interaction and does not indicate availability impact in the supplied CVSS data.
Recommended defensive actions
- Review the ICS-CERT and vendor-linked guidance referenced in the NVD record for any firmware update or mitigation steps.
- Restrict access to the device management interface to trusted administrative networks and users only.
- Use account separation and least privilege for administrative browsing sessions that access the device UI.
- Monitor for unexpected script behavior, session anomalies, or unusual input reflected in the interface.
- If a firmware update is available from Binom3, validate and deploy it according to your change-control process.
Evidence notes
This debrief is based on the official NVD CVE record and the references embedded in that record. The NVD metadata identifies the weakness as CWE-79 and lists the CVSS vector AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N. References include an ICS-CERT advisory (ICSA-17-031-01A) and a SecurityFocus BID entry. The supplied enrichment does not mark this CVE as KEV.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5164 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5164
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5164 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5164
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-17-031-01A
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.