PT-2018-6277 · Insteon · Insteon Hub
Published
2018-08-23
·
Updated
2023-01-28
·
CVE-2017-16348
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Insteon Hub version 1012
Description:
A denial of service issue exists due to leftover demo functionality, allowing an attacker to reboot the device without authentication by sending a UDP packet.
Recommendations:
For version 1012, consider disabling the demo functionality as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insteon Hub