An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: talos

Published: 2018-09-17T17:00:00

Updated: 2022-04-19T18:20:49

Reserved: 2017-09-13T00:00:00


Link: CVE-2017-14443

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-09-17T17:29:00.267

Modified: 2022-12-14T16:13:10.983


Link: CVE-2017-14443

JSON object: View

cve-icon Redhat Information

No data.

CWE