First published: Mon Sep 17 2018(Updated: )
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Insteon Hub 2245-222 Firmware | =1012 | |
Insteon Hub 2245-222 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14443 has been assigned a high severity due to its potential for sensitive information leakage.
To mitigate CVE-2017-14443, update the Insteon Hub to a firmware version that addresses this vulnerability.
CVE-2017-14443 affects the Insteon Hub running firmware version 1012.
Yes, CVE-2017-14443 can be exploited remotely through the HTTP server of the affected Insteon Hub.
CVE-2017-14443 can lead to arbitrary information leak from the device's memory, potentially exposing sensitive data.