Vulnerability Description
An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDbBody element in a StoreRules request to the upnp/control/rules1 URI, because database corruption occurs.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Belkin | Wemo Switch 28B Firmware | wemo_ww_2.00.11057.pvt-owrt-sns |
| Belkin | Wemo Switch 28B | - |
Related Weaknesses (CWE)
References
- https://github.com/badnack/wemo_dosExploitThird Party Advisory
- https://github.com/badnack/wemo_dosExploitThird Party Advisory
FAQ
What is CVE-2019-17532?
CVE-2019-17532 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on Belkin Wemo Switch 28B WW_2.00.11057.PVT-OWRT-SNS devices. They allow remote attackers to cause a denial of service (persistent rules-processing outage) via a crafted ruleDb...
How severe is CVE-2019-17532?
CVE-2019-17532 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17532?
Check the references section above for vendor advisories and patch information. Affected products include: Belkin Wemo Switch 28B Firmware, Belkin Wemo Switch 28B.