CVE-2017-5250
Summary
| CVE | CVE-2017-5250 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-02-22 16:29:00 UTC |
| Updated | 2019-10-09 23:28:00 UTC |
| Description | In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner. |
Risk And Classification
Problem Types: CWE-312 | CWE-922
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Insteon | Insteon For Hub | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple vulnerabilities in Wink and Insteon smart home systems | MISC | blog.rapid7.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.