{"api_version":"1","generated_at":"2026-07-23T08:25:03+00:00","cve":"CVE-2017-5250","urls":{"html":"https://cve.report/CVE-2017-5250","api":"https://cve.report/api/cve/CVE-2017-5250.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-5250","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-5250"},"summary":{"title":"CVE-2017-5250","description":"In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.","state":"PUBLIC","assigner":"cve@rapid7.com","published_at":"2018-02-22 16:29:00","updated_at":"2019-10-09 23:28:00"},"problem_types":["CWE-312","CWE-922"],"metrics":[],"references":[{"url":"https://blog.rapid7.com/2017/09/22/multiple-vulnerabilities-in-wink-and-insteon-smart-home-systems/","name":"https://blog.rapid7.com/2017/09/22/multiple-vulnerabilities-in-wink-and-insteon-smart-home-systems/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Multiple vulnerabilities in Wink and Insteon smart home systems","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-5250","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5250","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"5250","vulnerable":"1","versionEndIncluding":"1.9.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"insteon","cpe5":"insteon_for_hub","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"android","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@rapid7.com","ID":"CVE-2017-5250","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Insteon for Hub","version":{"version_data":[{"version_value":"1.9.7"}]}}]},"vendor_name":"Insteon"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-922 (Insecure Storage of Sensitive Information)"}]}]},"references":{"reference_data":[{"name":"https://blog.rapid7.com/2017/09/22/multiple-vulnerabilities-in-wink-and-insteon-smart-home-systems/","refsource":"MISC","url":"https://blog.rapid7.com/2017/09/22/multiple-vulnerabilities-in-wink-and-insteon-smart-home-systems/"}]}},"nvd":{"publishedDate":"2018-02-22 16:29:00","lastModifiedDate":"2019-10-09 23:28:00","problem_types":["CWE-312","CWE-922"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:insteon:insteon_for_hub:*:*:*:*:*:android:*:*","versionEndIncluding":"1.9.7","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"5250","Ordinal":"101765","Title":"CVE-2017-5250","CVE":"CVE-2017-5250","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"5250","Ordinal":"1","NoteData":"In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user access is not stored in an encrypted and secure manner.","Type":"Description","Title":null},{"CveYear":"2017","CveId":"5250","Ordinal":"2","NoteData":"2018-02-22","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"5250","Ordinal":"3","NoteData":"2018-02-22","Type":"Other","Title":"Modified"}]}}}