Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
2020-01-23T22:15:10.277
2024-11-21T05:34:58.290
Modified
CVSSv3.1: 7.9 (HIGH)
AV:A/AC:H/Au:N/C:P/I:P/A:P
3.2
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | philips | hue_bridge_v2_firmware | ≤ 1935144020 | Yes |
Hardware | philips | hue_bridge_v2 | - | No |