CVE-2016-5059 describes an information disclosure vulnerability in OSRAM SYLVANIA Osram Lightify Pro versions prior to 2016-07-26. Attackers could exploit this by reading screenshots stored in a specific directory, potentially revealing sensitive user data. This medium-severity vulnerability (CVSS 6.5) has a network attack vector and low attack complexity, allowing authenticated users to achieve high confidentiality impact without user interaction. There is no evidence of active exploitation, nor are public exploit modules like Metasploit or Nuclei available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= -CPE matchmatch criteria | cpe:2.3:a:osram:lightify_pro:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.