PatchSiren cyber security CVE debrief
CVE-2017-5165 Binom3 CVE debrief
CVE-2017-5165 is a cross-site request forgery (CSRF) issue affecting BINOM3 Universal Multifunctional Electric Power Quality Meter firmware. According to NVD, the flaw stems from missing CSRF tokens on pages and/or sensitive functions, which can let a remote attacker cause unauthorized device actions with no direct authentication, including configuration changes and saving modified settings.
- Vendor
- Binom3
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2017-02-07
- Advisory published
- 2017-01-31
- Advisory updated
- 2017-02-07
Who should care
Operators, maintainers, and integrators responsible for BINOM3 Universal Multifunctional Electric Power Quality Meter deployments should review this issue, especially where the device is exposed through a web interface on trusted networks or reachable from user browsers.
Technical summary
NVD identifies the weakness as CWE-352 and rates it CVSS 3.0 7.6 HIGH (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H). The supplied description says no CSRF token is generated per page and/or per sensitive function, enabling silent unauthorized actions such as configuration parameter changes and saving altered configuration. The NVD record includes a vulnerable firmware CPE for the BINOM3 meter and references ICS-CERT advisory ICSA-17-031-01A and SecurityFocus BID 93028.
Defensive priority
High for any environment where the device web interface is reachable by users who may browse untrusted content or where the device is operationally important. Because exploitation relies on user interaction but can change device configuration without direct credentials, it is a meaningful integrity and availability risk.
Recommended defensive actions
- Review the device web interface for CSRF protections on all state-changing requests.
- Restrict access to the management interface to trusted administrative networks only.
- Use browser and network segmentation controls to reduce the chance of unintended authenticated requests.
- Validate whether a vendor firmware update or advisory guidance is available through the referenced ICS-CERT advisory and NVD record.
- Monitor for unexpected configuration changes and save operations on affected meters.
Evidence notes
This debrief is based only on the supplied NVD record and referenced official/linked advisories. The corpus provides the vulnerability description, CVSS vector, and CWE-352 classification, but does not include a fixed firmware version range, patch release, or exploit details. NVD lists the issue as affecting BINOM3 Universal Multifunctional Electric Power Quality Meter firmware.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5165 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5165
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5165 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5165
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-17-031-01A
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.