CVE-2017-9488
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 address and then entering unspecified hardcoded credentials. This wan0 interface cannot be accessed from the public Internet.
El firmware Comcast en los dispositivos DPC3939 (versión de firmware dpc3939-P20-18-v303r20421746-170221a-CMCST) y DPC3941T (versión de firmware DPC3941_2.5s3_PROD_sey) de Cisco, permite que los atacantes remotos accedan a la interfaz de usuario web estableciendo una sesión para la dirección IPv6 de la WAN wan0 y luego ingresando credenciales codificadas no especificadas. Esta interfaz wan0 no se puede acceder a desde la Internet pública.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-06-07 CVE Reserved
- 2017-07-31 CVE Published
- 2023-12-15 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-798: Use of Hard-coded Credentials
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/BastilleResearch/CableTap/blob/master/doc/advisories/bastille-31.stb-remote-webui.txt | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Dpc3939 Firmware Search vendor "Cisco" for product "Dpc3939 Firmware" | dpc3939-p20-18-v303r20421746-170221a-cmcst Search vendor "Cisco" for product "Dpc3939 Firmware" and version "dpc3939-p20-18-v303r20421746-170221a-cmcst" | - |
Affected
| in | Cisco Search vendor "Cisco" | Dpc3939 Search vendor "Cisco" for product "Dpc3939" | - | - |
Safe
|
Cisco Search vendor "Cisco" | Dpc3941t Firmware Search vendor "Cisco" for product "Dpc3941t Firmware" | dpc3941_2.5s3_prod_sey Search vendor "Cisco" for product "Dpc3941t Firmware" and version "dpc3941_2.5s3_prod_sey" | - |
Affected
| in | Cisco Search vendor "Cisco" | Dpc3941t Search vendor "Cisco" for product "Dpc3941t" | - | - |
Safe
|