CVE-2018-11560
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
23/06/2018
Last modified:
22/06/2021
Description
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:insteon:2864-222_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:insteon:2864-222:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page