First published: Wed Jan 11 2023(Updated: )
Multiple exploitable buffer overflow vulnerabilities exists in the PubNub message handler for the "control" channel of Insteon Hub running firmware version 1012. Specially crafted replies received from the PubNub service can cause buffer overflows on a global section overwriting arbitrary data. An attacker should impersonate PubNub and answer an HTTPS GET request to trigger this vulnerability. The `strcpy` at [18] overflows the buffer `insteon_pubnub.channel_al`, which has a size of 16 bytes.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Insteon Hub Firmware | =1012 | |
Insteon Hub |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14454 has a high severity due to its potential to cause buffer overflows and overwrite arbitrary data.
To fix CVE-2017-14454, update the Insteon Hub to the latest firmware version that addresses the buffer overflow vulnerabilities.
CVE-2017-14454 affects Insteon Hub firmware version 1012.
CVE-2017-14454 is associated with multiple exploitable buffer overflow vulnerabilities.
Exploiting CVE-2017-14454 could allow attackers to execute arbitrary code and compromise the integrity of the Insteon Hub.