Vulnerabilities > Insteon > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-09-17 CVE-2017-14443 Information Exposure vulnerability in Insteon HUB 2245-222 Firmware 1012
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-200
6.5
2018-08-23 CVE-2017-14452 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Insteon HUB Firmware 1012
An exploitable buffer overflow vulnerability exists in the PubNub message handler for the "control" channel of Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-119
6.5
2018-08-06 CVE-2017-14447 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Insteon HUB Firmware 1012
An exploitable buffer overflow vulnerability exists in the PubNub message handler for the 'ad' channel of Insteon Hub running firmware version 1012.
network
low complexity
insteon CWE-119
5.5
2018-02-22 CVE-2017-5251 Missing Encryption of Sensitive Data vulnerability in Insteon HUB Firmware
In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and connected devices are not encrypted.
network
insteon CWE-311
6.8
2018-02-22 CVE-2017-5250 Insecure Storage of Sensitive Information vulnerability in Insteon FOR HUB
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
network
low complexity
insteon CWE-922
5.0