PT-2023-10568 · Insteon · Insteon Hub
Published
2023-01-11
·
Updated
2023-01-19
·
CVE-2017-16292
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Insteon Hub version 1012
Description
The issue concerns buffer overflow vulnerabilities in the PubNub message handler for the "cc" channel. These vulnerabilities can be triggered by sending specially crafted commands through the PubNub service, causing a stack-based buffer overflow that overwrites arbitrary data. An attacker must send an authenticated HTTP request to exploit this issue. Specifically, in the
cmd g schd, the value for the grp key is copied using strcpy to a buffer located at $sp+0x1b4, which is 8 bytes large. Sending data longer than this buffer size will cause a buffer overflow.Recommendations
For Insteon Hub version 1012, consider restricting access to the PubNub message handler for the "cc" channel until a patch is available. As a temporary workaround, avoid using the
grp key in the cmd g schd command to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Insteon Hub