First published: Thu Aug 02 2018(Updated: )
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bad0 the value for the host key is copied using strcpy to the buffer at 0xa00016e0. This buffer is 32 bytes large, sending anything longer will cause a buffer overflow.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Insteon Hub Firmware | =1012 | |
INSTEON Hub |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-16338 is rated as a high severity vulnerability due to the potential for remote exploitation via crafted requests.
To mitigate CVE-2017-16338, it is recommended to update the Insteon Hub firmware to a version beyond 1012.
CVE-2017-16338 is a buffer overflow vulnerability caused by improper input validation in the Insteon Hub firmware.
CVE-2017-16338 affects users of the Insteon Hub running firmware version 1012.
An attacker can exploit CVE-2017-16338 to execute arbitrary code on the Insteon Hub by sending a specially crafted HTTP request.