Tollgrade Smart Grid EMS LightHouse Vulnerabilities
Tollgrade LightHouse SMS Smart Grid Energy Management System (EMS) contains multiple vulnerabilities: improper access control (CWE-306) that allows authenticated users to read sensitive configuration and system information, information exposure (CWE-209) that leaks internal system details, and unrestricted upload/download (CWE-425). Affected versions: LightHouse SMS 5.1_Patch_3 and earlier. No firmware patches are planned by the vendor. The vulnerabilities enable authenticated attackers to access unauthorized resources and retrieve sensitive grid management data.
- Valid credentials for LightHouse SMS web interface
- Network access to the SMS server port
- Authentication to the application
Patching may require device reboot — plan for process interruption
/api/v1/advisories/56ee6d46-8b6a-4d33-b8b4-d94d1bc3fbddGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.