Stack-Based Buffer Overflow in Abode iota All-In-One Security Kit
CVE-2022-32454
10CRITICAL
Summary
A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of the iota All-In-One Security Kit from Abode Systems, Inc. Exploitation occurs when an attacker sends a specially-crafted XCMD command that includes a malicious XML payload. This vulnerability can allow remote code execution, posing significant security risks to the affected devices. Users are advised to update their systems promptly to mitigate the potential exploits associated with this vulnerability.
Affected Version(s)
iota All-In-One Security Kit 6.9X
iota All-In-One Security Kit 6.9Z
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved