PatchSiren cyber security CVE debrief
CVE-2017-5145 Carlosgavazzi CVE debrief
CVE-2017-5145 is a critical cross-site request forgery (CSRF) vulnerability affecting Carlo Gavazzi VMU-C EM firmware prior to Version A11_U05 and VMU-C PV firmware prior to Version A17. A successful attack can cause unauthorized actions on the device, including configuration parameter changes and saving modified configuration. Because the issue is network-reachable and requires no privileges, it is a high-priority risk for environments that expose device management interfaces to untrusted users or networks.
- Vendor
- Carlosgavazzi
- Product
- Unknown
- CVSS
- CRITICAL 10
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-12
- Original CVE updated
- 2017-01-12
- Advisory published
- 2017-01-12
- Advisory updated
- 2017-01-12
Who should care
Industrial control, building automation, and energy-management teams that operate Carlo Gavazzi VMU-C EM or VMU-C PV devices should care, especially administrators responsible for web-based device management, network segmentation, and firmware lifecycle management.
Technical summary
NVD lists the weakness as CWE-352 (CSRF) with CVSS v3.0 vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. The vulnerability affects VMU-C EM firmware versions before A11_U05 and VMU-C PV firmware versions before A17. The impact described in the CVE is unauthorized execution of device actions, including changing configuration parameters and saving altered settings.
Defensive priority
Critical. The combination of network attackability, no privileges, and potential impact to configuration integrity makes this a priority remediation item for any exposed or remotely managed deployment.
Recommended defensive actions
- Upgrade VMU-C EM firmware to Version A11_U05 or later.
- Upgrade VMU-C PV firmware to Version A17 or later.
- Restrict management access to trusted administrative networks and users only.
- Review whether the device web interface is reachable from untrusted segments and remove unnecessary exposure.
- Validate that administrative workflows do not rely on unsafe browser sessions or shared endpoints.
- Monitor and audit configuration changes on affected devices for unexpected modifications.
Evidence notes
This debrief is based on the CVE description and NVD metadata supplied in the source corpus. The CVE states the affected firmware thresholds and the CSRF impact directly. NVD identifies CWE-352 and the CVSS v3.0 vector. Official reference links include the CVE record and NVD detail page, plus the ICS-CERT advisory referenced in the NVD record. The CVE publication date used here is 2017-02-13; the later 2026-05-13 modified date is a metadata update, not the issue date.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5145 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5145
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5145 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5145
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://ics-cert.us-cert.gov/advisories/ICSA-17-012-03
[email protected] - Third Party Advisory, US Government Resource
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.