Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hxg7-68hm-96pc

Опубликовано: 25 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via controlURL XML tag, as used within the DoUpdateUPnPbyService action handler.

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via controlURL XML tag, as used within the DoUpdateUPnPbyService action handler.

EPSS

Процентиль: 33%
0.00134
Низкий

8.8 High

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `controlURL` XML tag, as used within the `DoUpdateUPnPbyService` action handler.

EPSS

Процентиль: 33%
0.00134
Низкий

8.8 High

CVSS3

Дефекты

CWE-134