PT-2017-17200 · Yes · Yesmaxtotal+2

Published

2017-09-07

·

Updated

2019-10-09

·

CVE-2017-6631

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions YesMaxTotal (affected versions not specified) YesMax HD (affected versions not specified) YesQuattro STB (affected versions not specified)
Description A vulnerability in the HTTP remote procedure call (RPC) service could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue exists because the firmware fails to handle certain XML values passed to the HTTP RPC service. An attacker could exploit this by submitting a malformed request, causing the device to restart and resulting in a DoS condition.
Recommendations For YesMaxTotal, update to the latest firmware provided by Yes to address the vulnerability. For YesMax HD, update to the latest firmware provided by Yes to address the vulnerability. For YesQuattro STB, update to the latest firmware provided by Yes to address the vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6631

Affected Products

Yesmax Hd
Yesmaxtotal
Yesquattro Stb