Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-29j9-ccp8-qccg

Опубликовано: 25 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the default_key_id and key HTTP parameters, as used within the /action/wirelessConnect handler.

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the default_key_id and key HTTP parameters, as used within the /action/wirelessConnect handler.

EPSS

Процентиль: 42%
0.00194
Низкий

8.8 High

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 8.8
nvd
почти 3 года назад

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` and `key` HTTP parameters, as used within the `/action/wirelessConnect` handler.

EPSS

Процентиль: 42%
0.00194
Низкий

8.8 High

CVSS3

Дефекты

CWE-134