PatchSiren cyber security CVE debrief
CVE-2017-5166 Binom3 CVE debrief
CVE-2017-5166 is a critical information exposure vulnerability in BINOM3 Universal Multifunctional Electric Power Quality Meter firmware. The publicly available record says exposed information can be used to gain privileged access to the device. NVD rates the issue CVSS 3.0 9.8 and maps it to CWE-200.
- Vendor
- Binom3
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-31
- Original CVE updated
- 2017-02-07
- Advisory published
- 2017-01-31
- Advisory updated
- 2017-02-07
Who should care
OT/ICS asset owners, site operators, network administrators, and security teams responsible for BINOM3 electric power quality meters or any industrial device deployed on reachable network segments.
Technical summary
The NVD record identifies the vulnerable component as BINOM3 Universal Multifunctional Electric Power Quality Meter firmware and classifies the weakness as CWE-200 (information exposure). The CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network-reachable exploitation with no privileges or user interaction required and severe potential impact. The record also references an ICS-CERT advisory and a SecurityFocus BID entry.
Defensive priority
Critical. Treat as urgent if the device or its management interface is reachable from any network beyond a tightly controlled OT segment.
Recommended defensive actions
- Inventory BINOM3 meter deployments and verify which devices run the affected firmware.
- Restrict network access to the meter and its management interfaces to required OT hosts only.
- Remove any unnecessary remote exposure, including direct Internet access and broad VLAN reachability.
- Review the referenced ICS-CERT advisory and vendor guidance for any remediation or mitigation steps.
- Monitor for unauthorized configuration access, privilege changes, and unexpected device behavior.
- If isolation is feasible, place affected devices on a segmented network with strict allow-listing and logging.
Evidence notes
This debrief is based on the supplied NVD record and its cited references. The record states an information exposure flaw, identifies BINOM3 firmware as vulnerable, assigns CWE-200, and gives CVSS 3.0 9.8. The supplied corpus does not provide affected firmware versions or a vendor patch status.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5166 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5166
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5166 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5166
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-17-031-01A
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.