PT-2017-11508 · Arris+1 · Arris Nvg589+2
Joseph Hutchins
+1
·
Published
2017-09-03
·
Updated
2021-08-23
·
CVE-2017-10793
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AT&T U-verse firmware version 9.2.2h0d83 for Arris NVG589 and NVG599 devices
Description
The issue concerns the configuration of an sbdc.ha WAN TCP service on port 61001 with a specific account and password, allowing remote attackers to obtain sensitive information, such as the Wi-Fi password, by leveraging knowledge of a hardware identifier. This is related to the Bulk Data Collection (BDC) mechanism.
Recommendations
For AT&T U-verse firmware version 9.2.2h0d83, consider disabling the sbdc.ha WAN TCP service on port 61001 as a temporary workaround until a patch is available. Restrict access to the bdctest account to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
At&T U-Verse
Arris Nvg589
Arris Nvg599