PT-2017-18967 · Motorola · Motorola Mx011Anm

Chris Grayson

+2

·

Publicado

2017-07-31

·

Atualizado

2017-08-02

·

CVE-2017-9497

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Comcast firmware on Motorola MX011ANM version MX011AN 2.9p6s1 PROD sey
Description The issue allows physically proximate attackers to execute arbitrary commands as root. This can be achieved by accessing the diagnostics menu on the set-top box and then posting to a Web Inspector route.
Recommendations For Comcast firmware on Motorola MX011ANM version MX011AN 2.9p6s1 PROD sey, consider restricting physical access to the set-top box to minimize the risk of exploitation. As a temporary workaround, limit access to the diagnostics menu and Web Inspector routes until a patch is available.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-9497

Produtos afetados

Motorola Mx011Anm