PT-2018-6275 · Insteon · Insteon Hub
Published
2018-08-02
·
Updated
2022-12-09
·
CVE-2017-16346
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Insteon Hub version 1012
Description:
The issue allows an attacker to send an authenticated HTTP request to trigger a buffer overflow. Specifically, the
s mac key value is copied to a 25-byte buffer using strcpy. Sending a value longer than 25 bytes will cause the buffer to overflow. The destination of the overflow can be shifted using the sn speaker parameter with values between 0 and 3.Recommendations:
For Insteon Hub version 1012, consider restricting access to authenticated HTTP requests until a patch is available. As a temporary workaround, avoid using the
sn speaker parameter to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insteon Hub