Blog | G5 Cyber Security

Vulnerability Spotlight: Information disclosure vulnerability in Blynk-Library

Cisco Talos discovered an information disclosure vulnerability in Blynk-Library. The vulnerability exists in the packet-parsing functionality of the library. A specially crafted packet can cause an unterminated strncpy, resulting in information disclosure. An attacker can send a packet to trigger this vulnerability. An update is available for affected customers and the vulnerability has been fixed. The following SNORT rules will detect exploitation attempts: Snort Rule: 50770, Firepower Management Center or Snort.org.”]

Source: https://blog.talosintelligence.com/2019/09/vulnerability-spotlight-information.html

Exit mobile version