// For flags

CVE-2017-17877

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.

Se ha descubierto un problema en la build 643 de Valve Steam Link. Cuando el demonio SSH está activado para desarrollo local, el dispositivo está disponible públicamente mediante el puerto 22 de TCP IPv6 en internet (con una autoconfiguración de dirección sin estado) por defecto. Esto facilita a los atacantes remotos obtener acceso adivinando 24 bits de la dirección MAC e intentando iniciar sesión como root. Esto se puede explotar junto con CVE-2017-17878.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2017-12-23 CVE Reserved
  • 2017-12-24 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Valvesoftware
Search vendor "Valvesoftware"
Steam Link Firmware
Search vendor "Valvesoftware" for product "Steam Link Firmware"
< 644
Search vendor "Valvesoftware" for product "Steam Link Firmware" and version " < 644"
-
Affected
in Valvesoftware
Search vendor "Valvesoftware"
Steam Link
Search vendor "Valvesoftware" for product "Steam Link"
--
Safe