Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-5146.
Includes Metasploit module auxiliary/scanner/http/gavazzi_em_login_loot.
AI-analyzed exploit summary This Metasploit module targets Carlo Gavazzi Energy Meters, performing brute-force login, firmware enumeration, SMTP configuration extraction, and database dumping via an access control vulnerability. It exploits CVE-2017-5146 to retrieve sensitive data without authentication in older firmware versions.
Description
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive information is stored in clear-text.
Exploits (1)
This Metasploit module targets Carlo Gavazzi Energy Meters, performing brute-force login, firmware enumeration, SMTP configuration extraction, and database dumping via an access control vulnerability. It exploits CVE-2017-5146 to retrieve sensitive data without authentication in older firmware versions.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N