PT-2019-7899 · Blipcare · Blipcare Wifi Blood Pressure Monitor Bp700

Mandar Satam

·

Publicado

2019-07-02

·

Atualizado

2019-07-15

·

CVE-2017-11580

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Blipcare Wifi blood pressure monitor BP700 version 10.1
Description The device allows memory corruption that results in Denial of Service. When connected to the "Blip" open wireless connection, if a large string is sent as part of the HTTP request in any part of the HTTP headers, the device could become completely unresponsive. This is due to the small memory footprint of the device, with the Wi-Fi module only having 256k of memory. An incorrect string copy operation using functions like memcpy or strcpy could result in filling up the memory space allocated to the function executing, leading to memory corruption.
Recommendations For Blipcare Wifi blood pressure monitor BP700 version 10.1, as a temporary workaround, consider restricting access to the device's open wireless connection "Blip" to minimize the risk of exploitation. Avoid sending large strings as part of the HTTP request in any part of the HTTP headers until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11580

Produtos afetados

Blipcare Wifi Blood Pressure Monitor Bp700