PT-2018-16228 · Insteon · Insteon Hub
Published
2018-08-02
·
Updated
2023-02-03
·
CVE-2018-3834
CVSS v3.1
8.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Insteon Hub version 1013
Description
An exploitable permanent denial of service issue exists due to the firmware upgrade functionality retrieving signed firmware binaries using plain HTTP requests. The device does not check the type of firmware image to be installed, allowing any signed firmware to be flashed into any MCU. Since the device contains different and incompatible MCUs, flashing one firmware to the wrong MCU results in a permanent brick condition. To trigger this issue, an attacker needs to impersonate the remote server "cache.insteon.com" and serve a signed firmware image.
Recommendations
For Insteon Hub version 1013, consider disabling the firmware upgrade functionality via PubNub until a secure update is available to prevent exploitation. Restrict access to the device to minimize the risk of an attacker impersonating the remote server "cache.insteon.com". At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insteon Hub