Vulnerabilities > Tollgrade > Lighthouse SMS
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2016-07-15 | CVE-2016-5807 | Improper Access Control vulnerability in Tollgrade Lighthouse SMS Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request. | 8.1 |
2016-07-15 | CVE-2016-5797 | Information Exposure vulnerability in Tollgrade Lighthouse SMS Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts. | 5.3 |