Format String Injection Vulnerability in Abode Systems iota All-In-One Security Kit
CVE-2022-33938
What is CVE-2022-33938?
A format string injection vulnerability exists within the ghome_process_control_packet feature of the iota All-In-One Security Kit produced by Abode Systems, Inc. This vulnerability can be exploited through specially crafted XML payloads that utilize the XCMD mechanism, potentially leading to serious consequences including memory corruption, information disclosure, and denial of service events. Attackers may exploit this flaw by sending malicious input to the affected devices, compromising their operational integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
iota All-In-One Security Kit 6.9X
iota All-In-One Security Kit 6.9Z
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved