First published: Thu Oct 20 2022(Updated: )
A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Goabode Iota All-in-one Security Kit Firmware | =6.9z | |
Goabode Iota All-in-one Security Kit | ||
Goabode Iota All-in-one Security Kit Firmware | =6.9x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35244 is a format string injection vulnerability in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z.
CVE-2022-35244 has a severity rating of 9.8 (critical).
A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service.
The affected software versions are abode systems, inc. iota All-In-One Security Kit firmware versions 6.9X and 6.9Z.
Currently, there is no known fix or patch available for CVE-2022-35244. It is recommended to follow the vendor's guidance and monitor for any updates.