HIGH · 7.5

CVE-2019-17532

An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDb...

Vulnerability Description

An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
BelkinWemo Switch 28B Firmwarewemo_ww_2.00.11057.pvt-owrt-sns
BelkinWemo Switch 28B-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-17532?

CVE-2019-17532 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDb...

How severe is CVE-2019-17532?

CVE-2019-17532 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-17532?

Check the references section above for vendor advisories and patch information. Affected products include: Belkin Wemo Switch 28B Firmware, Belkin Wemo Switch 28B.