Tollgrade develops a niche smart-grid sensor management platform, the Lighthouse SMS, whose vulnerabilities concentrate in web-application and access-control domains including sensitive-information disclosure, cross-site request forgery, improper access control, and cross-site scripting. The recurring weakness classes reflect typical risks in web-facing administrative interfaces for distributed infrastructure management. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tollgrade over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5807HIGH Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, | Jul 15, 2016 | 8.1 | 26 | NO | NO |
CVE-2016-0865HIGH Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspe | Feb 13, 2016 | 8.8 | 25 | NO | NO |
CVE-2016-0863HIGH Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attacker | Feb 13, 2016 | 8.8 | 24 | NO | NO |
CVE-2016-0866MEDIUM Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to in | Feb 13, 2016 | 6.1 | 20 | NO | NO |
CVE-2016-5797MEDIUM Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attac | Jul 15, 2016 | 5.3 | 16 | NO | NO |
CVE-2016-0864MEDIUM Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username informati | Feb 13, 2016 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tollgrade.
Media articles that mention a CVE ID that affects a product developed by Tollgrade — matched by CVE ID, not by vendor name.