First published: Thu Aug 02 2018(Updated: )
An attacker could send an authenticated HTTP request to trigger this vulnerability in Insteon Hub running firmware version 1012. At 0x9d01bb1c the value for the uri key is copied using strcpy to the buffer at 0xa00016a0. This buffer is 64 bytes large, sending anything longer will cause a buffer overflow.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Insteon Hub Firmware | =1012 | |
INSTEON Hub |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-16339 is considered high due to the potential for remote code execution via a buffer overflow.
To fix CVE-2017-16339, update the Insteon Hub firmware to the latest version provided by the manufacturer.
CVE-2017-16339 specifically affects the Insteon Hub running firmware version 1012.
Yes, CVE-2017-16339 can be exploited remotely by sending an authenticated HTTP request to the Insteon Hub.
CVE-2017-16339 is a buffer overflow vulnerability that occurs when an attacker sends overly long input to the URI key.