PT-2017-18952 · Cisco · Cisco Dpc3939

Chris Grayson

+2

·

Publicado

2017-07-31

·

Atualizado

2017-08-02

·

CVE-2017-9480

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST
Description The issue allows local users with command access to read arbitrary files via UPnP access to the /var/IGD/ directory. This can be exploited by users who have gained command access as a result of previous exploitation.
Recommendations For Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST, consider restricting access to the /var/IGD/ directory to minimize the risk of exploitation. As a temporary workaround, disabling UPnP access until a patch is available can help mitigate the issue.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9480

Produtos afetados

Cisco Dpc3939