CVE ID | |
CVSS SCORE | 6.1, AV:A/AC:L/Au:N/C:N/I:N/A:C |
AFFECTED VENDORS |
Belkin |
AFFECTED PRODUCTS |
Wemo Link |
TREND MICRO CUSTOMER PROTECTION | Trend Micro TippingPoint IPS customers are protected against this vulnerability by Digital Vaccine protection filter ID ['29835']. For further product information on the TippingPoint IPS: http://www.tippingpoint.com |
VULNERABILITY DETAILS |
The specific flaw exists within the handling of XML parsing in the UPNP service. When parsing changeFriendlyName requests, the process does not properly validate the length of user-supplied data prior to copying it to a buffer. An attacker can leverage this vulnerability to trigger an infinite reboot loop and deny service to users of the device.
|
ADDITIONAL DETAILS |
09/07/17 - ZDI reported vulnerability to vendor -- Mitigation: |
DISCLOSURE TIMELINE |
|
CREDIT | Dove Chiu of Trend Micro |