CVE-2017-9392 describes a critical buffer overflow vulnerability in Vera VeraEdge and Veralite devices, specifically affecting firmware versions 1.7.19 and 1.7.481 respectively. This flaw, residing in the UPnP "request_image" service, allows an authenticated attacker to execute arbitrary code by sending an overly long "res" parameter, which is unsafely copied to a stack buffer. With a CVSS score of 8.8 (High), the vulnerability is network-exploitable with low attack complexity, requiring only low privileges, and can lead to complete compromise of confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) or active exploitation has been observed, and community discussion is minimal, the high risk score and potential for remote code execution warrant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.7.19CPE matchmatch criteria | cpe:2.3:o:getvera:veraedge_firmware:*:*:*:*:*:*:*:* | ||
<= 1.7.481CPE matchmatch criteria | cpe:2.3:o:getvera:veralite_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.