ID

VAR-201808-0082


CVE

CVE-2017-14447


TITLE

Insteon Hub Firmware buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-014194

DESCRIPTION

An exploitable buffer overflow vulnerability exists in the PubNub message handler for the 'ad' channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability. Insteon Hub The firmware contains a buffer error vulnerability.Information may be tampered with. InsteonHub is an Insteon central controller from Insteon, USA. This product can remotely control light bulbs, wall switches, air conditioners, etc. in the home. Insteon Hub is an Insteon central controller product of Insteon Company in the United States

Trust: 2.25

sources: NVD: CVE-2017-14447 // JVNDB: JVNDB-2017-014194 // CNVD: CNVD-2018-16501 // VULHUB: VHN-105170

IOT TAXONOMY

category:['Network device']sub_category:Gateway / Hub: Open Ecosystem

Trust: 0.6

category:['home & office device']sub_category:smart home device

Trust: 0.1

category:['home & office device']sub_category:smart home controller

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2018-16501

AFFECTED PRODUCTS

vendor:insteonmodel:hubscope:eqversion:1012

Trust: 3.0

sources: CNVD: CNVD-2018-16501 // JVNDB: JVNDB-2017-014194 // CNNVD: CNNVD-201709-621 // NVD: CVE-2017-14447

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-14447
value: HIGH

Trust: 1.0

talos-cna@cisco.com: CVE-2017-14447
value: HIGH

Trust: 1.0

NVD: CVE-2017-14447
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-16501
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201709-621
value: HIGH

Trust: 0.6

VULHUB: VHN-105170
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-14447
severity: MEDIUM
baseScore: 5.5
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-16501
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-105170
severity: MEDIUM
baseScore: 5.5
vectorString: AV:N/AC:L/AU:S/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 8.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-14447
baseSeverity: HIGH
baseScore: 7.7
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 3.1
impactScore: 4.0
version: 3.0

Trust: 1.8

talos-cna@cisco.com: CVE-2017-14447
baseSeverity: HIGH
baseScore: 8.5
vectorString: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 6.0
version: 3.0

Trust: 1.0

sources: CNVD: CNVD-2018-16501 // VULHUB: VHN-105170 // JVNDB: JVNDB-2017-014194 // CNNVD: CNNVD-201709-621 // NVD: CVE-2017-14447 // NVD: CVE-2017-14447

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-105170 // JVNDB: JVNDB-2017-014194 // NVD: CVE-2017-14447

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201709-621

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201709-621

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014194

PATCH

title:Top Pageurl:https://www.insteon.com

Trust: 0.8

sources: JVNDB: JVNDB-2017-014194

EXTERNAL IDS

db:NVDid:CVE-2017-14447

Trust: 3.2

db:TALOSid:TALOS-2017-0496

Trust: 2.5

db:JVNDBid:JVNDB-2017-014194

Trust: 0.8

db:CNNVDid:CNNVD-201709-621

Trust: 0.7

db:CNVDid:CNVD-2018-16501

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

db:SEEBUGid:SSVID-97361

Trust: 0.1

db:VULHUBid:VHN-105170

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2018-16501 // VULHUB: VHN-105170 // JVNDB: JVNDB-2017-014194 // CNNVD: CNNVD-201709-621 // NVD: CVE-2017-14447

REFERENCES

url:https://www.talosintelligence.com/vulnerability_reports/talos-2017-0496

Trust: 1.9

url:https://nvd.nist.gov/vuln/detail/cve-2017-14447

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-14447

Trust: 0.8

url:https://talosintelligence.com/vulnerability_reports/talos-2017-0496

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNVD: CNVD-2018-16501 // VULHUB: VHN-105170 // JVNDB: JVNDB-2017-014194 // CNNVD: CNNVD-201709-621 // NVD: CVE-2017-14447

SOURCES

db:OTHERid: -
db:CNVDid:CNVD-2018-16501
db:VULHUBid:VHN-105170
db:JVNDBid:JVNDB-2017-014194
db:CNNVDid:CNNVD-201709-621
db:NVDid:CVE-2017-14447

LAST UPDATE DATE

2025-01-30T20:53:21.612000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-16501date:2018-08-28T00:00:00
db:VULHUBid:VHN-105170date:2018-10-16T00:00:00
db:JVNDBid:JVNDB-2017-014194date:2018-11-12T00:00:00
db:CNNVDid:CNNVD-201709-621date:2022-04-20T00:00:00
db:NVDid:CVE-2017-14447date:2024-11-21T03:12:48.823

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-16501date:2018-08-28T00:00:00
db:VULHUBid:VHN-105170date:2018-08-06T00:00:00
db:JVNDBid:JVNDB-2017-014194date:2018-11-12T00:00:00
db:CNNVDid:CNNVD-201709-621date:2017-09-15T00:00:00
db:NVDid:CVE-2017-14447date:2018-08-06T17:29:01.303