CVE-2017-17877
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.
Se ha descubierto un problema en la build 643 de Valve Steam Link. Cuando el demonio SSH está activado para desarrollo local, el dispositivo está disponible públicamente mediante el puerto 22 de TCP IPv6 en internet (con una autoconfiguración de dirección sin estado) por defecto. Esto facilita a los atacantes remotos obtener acceso adivinando 24 bits de la dirección MAC e intentando iniciar sesión como root. Esto se puede explotar junto con CVE-2017-17878.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-23 CVE Reserved
- 2017-12-24 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://blogger.davidmanouchehri.com/2017/12/steam-link-security-remotely-insecure.html | Issue Tracking | |
https://github.com/ValveSoftware/steamlink-sdk#ssh-access | Issue Tracking | |
https://github.com/ValveSoftware/steamlink-sdk/issues/119 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Valvesoftware Search vendor "Valvesoftware" | Steam Link Firmware Search vendor "Valvesoftware" for product "Steam Link Firmware" | < 644 Search vendor "Valvesoftware" for product "Steam Link Firmware" and version " < 644" | - |
Affected
| in | Valvesoftware Search vendor "Valvesoftware" | Steam Link Search vendor "Valvesoftware" for product "Steam Link" | - | - |
Safe
|