PT-2023-10539 · Insteon · Insteon Hub
Published
2023-01-11
·
Updated
2023-01-23
·
CVE-2017-16263
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Insteon Hub version 1012
Description
The issue concerns buffer overflow vulnerabilities in the PubNub message handler for the "cc" channel. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow, overwriting arbitrary data. An attacker must send an authenticated HTTP request to trigger this issue. Specifically, in the
cmd g b function, the value for the val key is copied using strcpy to a 32-byte buffer, and sending data longer than this will cause a buffer overflow.Recommendations
For Insteon Hub version 1012, consider restricting access to the PubNub service until a patch is available, and avoid using the
cmd g b function with untrusted input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Insteon Hub