Osram's vulnerability profile centers on its smart-lighting platforms, Lightify Pro and Lightify Home, which connect consumer and commercial lighting systems to networked control. The exposures skew toward serious outcomes and recur through authentication, encryption, and web-interface weakness classes including improper access control, sensitive-information disclosure, and cross-site scripting, reflecting the intersection of IoT device management and cloud connectivity. Current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Osram over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5053CRITICAL OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port 4000. | Apr 10, 2017 | 9.8 | 31 | NO | NO |
CVE-2016-5051HIGH OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application. | Apr 10, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-5059MEDIUM OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application. | Apr 10, 2017 | 6.5 | 23 | NO | NO |
CVE-2016-5057HIGH OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning. | Apr 10, 2017 | 7.5 | 22 | NO | NO |
CVE-2016-5056HIGH OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK. | Apr 10, 2017 | 7.5 | 22 | NO | NO |
CVE-2016-5054HIGH OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay. | Apr 10, 2017 | 7.5 | 22 | NO | NO |
CVE-2016-5052HIGH OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning. | Apr 10, 2017 | 7.5 | 22 | NO | NO |
CVE-2016-5058HIGH OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay. | Apr 10, 2017 | 7.5 | 21 | NO | NO |
CVE-2016-5055MEDIUM OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page. | Apr 10, 2017 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Osram.
Media articles that mention a CVE ID that affects a product developed by Osram — matched by CVE ID, not by vendor name.