PT-2022-22996 · Abode Systems · Iota All-In-One Security Kit
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Abode Systems, Inc. iota All-In-One Security Kit versions 6.9Z through 6.9X
Description
The web interface /action/wirelessConnect functionality contains format string injection vulnerabilities. A specially-crafted HTTP request can lead to memory corruption, information disclosure, and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities via the
default key id and key HTTP parameters within the /action/wirelessConnect handler.Recommendations
For versions 6.9Z through 6.9X, consider disabling the
/action/wirelessConnect functionality until a patch is available to prevent exploitation through the default key id and key parameters. Restrict access to the /action/wirelessConnect handler to minimize the risk of exploitation. Avoid using the default key id and key parameters in the affected API endpoint until the issue is resolved.Exploit
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Iota All-In-One Security Kit