PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5166 Binom3 CVE debrief

CVE-2017-5166 is a critical information exposure vulnerability in BINOM3 Universal Multifunctional Electric Power Quality Meter firmware. The publicly available record says exposed information can be used to gain privileged access to the device. NVD rates the issue CVSS 3.0 9.8 and maps it to CWE-200.

Vendor
Binom3
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-31
Original CVE updated
2017-02-07
Advisory published
2017-01-31
Advisory updated
2017-02-07

Who should care

OT/ICS asset owners, site operators, network administrators, and security teams responsible for BINOM3 electric power quality meters or any industrial device deployed on reachable network segments.

Technical summary

The NVD record identifies the vulnerable component as BINOM3 Universal Multifunctional Electric Power Quality Meter firmware and classifies the weakness as CWE-200 (information exposure). The CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-reachable exploitation with no privileges or user interaction required and severe potential impact. The record also references an ICS-CERT advisory and a SecurityFocus BID entry.

Defensive priority

Critical. Treat as urgent if the device or its management interface is reachable from any network beyond a tightly controlled OT segment.

Recommended defensive actions

  • Inventory BINOM3 meter deployments and verify which devices run the affected firmware.
  • Restrict network access to the meter and its management interfaces to required OT hosts only.
  • Remove any unnecessary remote exposure, including direct Internet access and broad VLAN reachability.
  • Review the referenced ICS-CERT advisory and vendor guidance for any remediation or mitigation steps.
  • Monitor for unauthorized configuration access, privilege changes, and unexpected device behavior.
  • If isolation is feasible, place affected devices on a segmented network with strict allow-listing and logging.

Evidence notes

This debrief is based on the supplied NVD record and its cited references. The record states an information exposure flaw, identifies BINOM3 firmware as vulnerable, assigns CWE-200, and gives CVSS 3.0 9.8. The supplied corpus does not provide affected firmware versions or a vendor patch status.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5166 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5166

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5166 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5166

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.