Vulnerabilities > Tollgrade > Lighthouse SMS

DATE CVE VULNERABILITY TITLE RISK
2016-07-15 CVE-2016-5807 Improper Access Control vulnerability in Tollgrade Lighthouse SMS
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request.
network
low complexity
tollgrade CWE-284
8.1
2016-07-15 CVE-2016-5797 Information Exposure vulnerability in Tollgrade Lighthouse SMS
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
network
low complexity
tollgrade CWE-200
5.3