Vulnerabilities > Insteon > High

DATE CVE VULNERABILITY TITLE RISK
2018-08-23 CVE-2018-3833 Unspecified vulnerability in Insteon HUB 2245-222 Firmware 1013
An exploitable firmware downgrade vulnerability exists in Insteon Hub running firmware version 1013.
network
low complexity
insteon
7.5
2018-08-23 CVE-2017-16348 Improper Authentication vulnerability in Insteon HUB Firmware 1012
An exploitable denial of service vulnerability exists in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-287
7.5
2018-08-06 CVE-2017-16252 Out-of-bounds Write vulnerability in Insteon HUB Firmware 1012
Specially crafted commands sent through the PubNub service in Insteon Hub 2245-222 with firmware version 1012 can cause a stack-based buffer overflow overwriting arbitrary data.
network
low complexity
insteon CWE-787
8.1
2018-08-06 CVE-2017-14447 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Insteon HUB Firmware 1012
An exploitable buffer overflow vulnerability exists in the PubNub message handler for the 'ad' channel of Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-119
7.7
2018-08-02 CVE-2018-3834 Origin Validation Error vulnerability in Insteon HUB Firmware 1013
An exploitable permanent denial of service vulnerability exists in Insteon Hub running firmware version 1013.
network
high complexity
insteon CWE-346
7.4
2018-02-22 CVE-2017-5251 Missing Encryption of Sensitive Data vulnerability in Insteon HUB Firmware
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
network
high complexity
insteon CWE-311
8.1