PT-2018-16227 · Insteon · Insteon Hub
CVE-2018-3833
·
Publicado
2018-08-23
·
Atualizado
2023-02-03
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Insteon Hub version 1013
Description
An exploitable issue exists in the firmware upgrade functionality of the Insteon Hub, triggered via PubNub. The device retrieves signed firmware binaries using plain HTTP requests and does not check the firmware version to be installed, allowing for the installation of older firmware images. To exploit this, an attacker must impersonate the remote server 'cache.insteon.com' and serve any signed firmware image.
Recommendations
For version 1013, consider disabling the firmware upgrade functionality via PubNub until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of an attacker impersonating the 'cache.insteon.com' server. Avoid using plain HTTP requests for firmware updates until the issue is resolved.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Insteon Hub