PT-2017-11508 · Arris+1 · Arris Nvg589+2

Joseph Hutchins

+1

·

Published

2017-09-03

·

Updated

2021-08-23

·

CVE-2017-10793

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AT&T U-verse firmware version 9.2.2h0d83 for Arris NVG589 and NVG599 devices
Description The issue concerns the configuration of an sbdc.ha WAN TCP service on port 61001 with a specific account and password, allowing remote attackers to obtain sensitive information, such as the Wi-Fi password, by leveraging knowledge of a hardware identifier. This is related to the Bulk Data Collection (BDC) mechanism.
Recommendations For AT&T U-verse firmware version 9.2.2h0d83, consider disabling the sbdc.ha WAN TCP service on port 61001 as a temporary workaround until a patch is available. Restrict access to the bdctest account to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-10793

Affected Products

At&T U-Verse
Arris Nvg589
Arris Nvg599