Vulnerability Details CVE-2017-14443
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.2%
CVSS Severity
CVSS v3 Score 9.6
CVSS v2 Score 4.0
Products affected by CVE-2017-14443
-
cpe:2.3:h:insteon:hub_2245-222:-
-
cpe:2.3:o:insteon:hub_2245-222_firmware:1012