Vulnerabilities > CVE-2020-6007 - Out-of-bounds Write vulnerability in Philips HUE Bridge V2 Firmware

047910
CVSS 7.9 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
high complexity
philips
CWE-787

Summary

Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.

Vulnerable Configurations

Part Description Count
OS
Philips
34
Hardware
Philips
1

Common Weakness Enumeration (CWE)

The Hacker News

idTHN:E890F3397DAC75C42DB476D17217A3CB
last seen2020-02-05
modified2020-02-05
published2020-02-05
reporterThe Hacker News
sourcehttps://thehackernews.com/2020/02/philips-smart-light-bulb-hacking.html
titleFlaw in Philips Smart Light Bulbs Exposes Your WiFi Network to Hackers