CVE-2016-5051 describes a vulnerability in OSRAM SYLVANIA Osram Lightify Home versions prior to 2016-07-26, where the Pre-Shared Key (PSK) is stored in cleartext within the application's data directory. This critical information disclosure vulnerability carries a CVSS score of 7.5 (High), indicating that an unauthenticated attacker could remotely access the PSK with low attack complexity, leading to a complete compromise of confidentiality. Despite its high severity, there is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage for this CVE are minimal, suggesting limited public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.6.1CPE matchmatch criteria | cpe:2.3:a:osram:lightify_home:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.