PT-2018-6275 · Insteon · Insteon Hub
CVE-2017-16346
·
Publicado
2018-08-02
·
Atualizado
2022-12-09
CVSS v3.1
9.9
Crítica
| Vetor | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Insteon Hub version 1012
Description:
The issue allows an attacker to send an authenticated HTTP request to trigger a buffer overflow. Specifically, the
s mac key value is copied to a 25-byte buffer using strcpy. Sending a value longer than 25 bytes will cause the buffer to overflow. The destination of the overflow can be shifted using the sn speaker parameter with values between 0 and 3.Recommendations:
For Insteon Hub version 1012, consider restricting access to authenticated HTTP requests until a patch is available. As a temporary workaround, avoid using the
sn speaker parameter to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Insteon Hub