First published: Thu Aug 02 2018(Updated: )
An exploitable stack-based buffer overflow vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation unsafely extracts parameters from the query string, leading to a buffer overflow on the stack. An attacker can send an HTTP GET request to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Insteon Hub Firmware | =1012 | |
Insteon Hub |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14446 is classified as a high severity vulnerability due to the potential for remote code execution.
To remediate CVE-2017-14446, update the Insteon Hub to firmware version that is higher than 1012.
CVE-2017-14446 is a stack-based buffer overflow vulnerability in the Insteon Hub's HTTP server implementation.
An attacker can exploit CVE-2017-14446 by sending a crafted HTTP GET request that triggers a buffer overflow.
CVE-2017-14446 specifically affects Insteon Hub running firmware version 1012.