PT-2022-22994 · Abode Systems · Iota All-In-One Security Kit

Matt Wiseman

·

Published

2022-10-25

·

Updated

2022-10-27

·

CVE-2022-35884

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Abode Systems, Inc. iota All-In-One Security Kit versions 6.9Z through 6.9X
Description The web interface of the affected system has format string injection vulnerabilities in the /action/wirelessConnect functionality. A specially-crafted HTTP request can cause memory corruption, information disclosure, and denial of service. An attacker can trigger these vulnerabilities by making an authenticated HTTP request. The issue arises from format string injection via the ssid hex HTTP parameter used within the /action/wirelessConnect handler.
Recommendations For versions 6.9Z through 6.9X, consider disabling the /action/wirelessConnect functionality until a patch is available to prevent exploitation via the ssid hex parameter. Avoid using the ssid hex parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2022-35884

Affected Products

Iota All-In-One Security Kit