ZeroHour

CVE-2017-14443

PoC
CVSS 3.1
6.5 medium
EPSS
2%p77
Published
()
Modified
Description

An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.

Vendors
insteon
Products
hub 2245-222 firmware
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news