PT-2017-18961 · Cisco+1 · Cisco Dpc3939B+3
Chris Grayson
+2
·
Publicado
2017-07-31
·
Atualizado
2021-09-13
·
CVE-2017-9491
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco DPC3939 version dpc3939-P20-18-v303r20421733-160420a-CMCST
Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST
Cisco DPC3939B version dpc3939b-v303r204217-150321a-CMCST
Cisco DPC3941T version DPC3941 2.5s3 PROD sey
Arris TG1682G version 10.0.132.SIP.PC20.CT, software version TG1682 2.2p7s2 PROD sey
Description
The Comcast firmware on the affected devices does not set the secure flag for cookies in an https session to an administration application. This makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
Recommendations
For Cisco DPC3939 version dpc3939-P20-18-v303r20421733-160420a-CMCST, consider disabling access to the administration application until a patch is available.
For Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST, consider disabling access to the administration application until a patch is available.
For Cisco DPC3939B version dpc3939b-v303r204217-150321a-CMCST, consider disabling access to the administration application until a patch is available.
For Cisco DPC3941T version DPC3941 2.5s3 PROD sey, consider disabling access to the administration application until a patch is available.
For Arris TG1682G version 10.0.132.SIP.PC20.CT, software version TG1682 2.2p7s2 PROD sey, consider disabling access to the administration application until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Arris Tg1682G
Cisco Dpc3939
Cisco Dpc3939B
Cisco Dpc3941T