First published: Sat Oct 12 2019(Updated: )
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Belkin Wemo Switch 28b Firmware | =wemo_ww_2.00.11057.pvt-owrt-sns | |
Belkin Wemo Switch 28B |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-17532.
The severity of CVE-2019-17532 is high with a score of 7.5.
CVE-2019-17532 allows remote attackers to cause a denial of service (persistent rules-processing outage) on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices.
This vulnerability can be exploited by sending a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI.
At the time of writing, there is no known fix or patch available for CVE-2019-17532. It is recommended to apply any security updates provided by the vendor.