CVE-2020-6007

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
23/01/2020
Last modified:
01/03/2023

Description

Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:philips:hue_bridge_v2_firmware:*:*:*:*:*:*:*:* 1935144020 (including)
cpe:2.3:h:philips:hue_bridge_v2:-:*:*:*:*:*:*:*