Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to trigger these vulnerabilities.This vulnerability arises from format string injection via `NewInternalClient` XML tag, as used within the `DoUpdateUPnPbyService` action handler.
CVSS Information
N/A
Vulnerability Type
使用外部控制的格式字符串
Vulnerability Title
Abode Iota 格式化字符串错误漏洞
Vulnerability Description
Abode Iota是Abode公司的一个可靠的 Diy 家庭安全系统。 Abode Iota 6.9X和6.9Z版本存在格式化字符串错误漏洞,该漏洞源于攻击者可以托管恶意的UPnP服务通过其日志功能导致内存损坏、信息泄露和拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A