CVE-2020-6007
Severity CVSS v4.0:
Pending analysis
Type:
CWE-787
Out-of-bounds Write
Publication date:
23/01/2020
Last modified:
01/03/2023
Description
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
Impact
Base Score 3.x
7.90
Severity 3.x
HIGH
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:philips:hue_bridge_v2_firmware:*:*:*:*:*:*:*:* | 1935144020 (including) | |
cpe:2.3:h:philips:hue_bridge_v2:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page