PT-2017-18961 · Cisco+1 · Cisco Dpc3939B+3

Chris Grayson

+2

·

Publicado

2017-07-31

·

Atualizado

2021-09-13

·

CVE-2017-9491

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco DPC3939 version dpc3939-P20-18-v303r20421733-160420a-CMCST Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST Cisco DPC3939B version dpc3939b-v303r204217-150321a-CMCST Cisco DPC3941T version DPC3941 2.5s3 PROD sey Arris TG1682G version 10.0.132.SIP.PC20.CT, software version TG1682 2.2p7s2 PROD sey
Description The Comcast firmware on the affected devices does not set the secure flag for cookies in an https session to an administration application. This makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
Recommendations For Cisco DPC3939 version dpc3939-P20-18-v303r20421733-160420a-CMCST, consider disabling access to the administration application until a patch is available. For Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST, consider disabling access to the administration application until a patch is available. For Cisco DPC3939B version dpc3939b-v303r204217-150321a-CMCST, consider disabling access to the administration application until a patch is available. For Cisco DPC3941T version DPC3941 2.5s3 PROD sey, consider disabling access to the administration application until a patch is available. For Arris TG1682G version 10.0.132.SIP.PC20.CT, software version TG1682 2.2p7s2 PROD sey, consider disabling access to the administration application until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9491

Produtos afetados

Arris Tg1682G
Cisco Dpc3939
Cisco Dpc3939B
Cisco Dpc3941T