Vulnerability Description
In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insteon | Insteon For Hub | <= 1.9.7 |
Related Weaknesses (CWE)
References
- https://blog.rapid7.com/2017/09/22/multiple-vulnerabilities-in-wink-and-insteon-Third Party Advisory
- https://blog.rapid7.com/2017/09/22/multiple-vulnerabilities-in-wink-and-insteon-Third Party Advisory
FAQ
What is CVE-2017-5250?
CVE-2017-5250 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.
How severe is CVE-2017-5250?
CVE-2017-5250 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2017-5250?
Check the references section above for vendor advisories and patch information. Affected products include: Insteon Insteon For Hub.