PT-2017-3500 · Valve · Valve Steam Link

Publicado

2017-12-22

·

Atualizado

2019-10-03

·

CVE-2017-17877

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Valve Steam Link build 643
Description The issue is related to inadequate access control in the Valve Steam Link device. When the SSH daemon is enabled for local development, the device becomes publicly accessible via IPv6 TCP port 22 over the internet by default. This makes it easier for remote attackers to gain access by guessing 24 bits of the MAC address and attempting a root login.
Recommendations For Valve Steam Link build 643, consider disabling the SSH daemon when not in use for local development to prevent unauthorized access. Restrict access to IPv6 TCP port 22 to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00328
CVE-2017-17877

Produtos afetados

Valve Steam Link