First published: Tue Oct 25 2022(Updated: )
A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Goabode Iota All-in-one Security Kit Firmware | =6.9z | |
Goabode Iota All-in-one Security Kit | ||
Goabode Iota All-in-one Security Kit Firmware | =6.9x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-33938 is a format string injection vulnerability that exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X.
CVE-2022-33938 has a severity rating of 9.8, which is considered critical.
The affected software of CVE-2022-33938 is Goabode Iota All-in-one Security Kit Firmware versions 6.9Z and 6.9X.
CVE-2022-33938 can lead to memory corruption, information disclosure, and denial of service.
Currently, there is no known fix available for CVE-2022-33938. It is recommended to follow the guidance provided by the vendor or security advisory.