PT-2017-17200 · Yes · Yesmaxtotal+2
Published
2017-09-07
·
Updated
2019-10-09
·
CVE-2017-6631
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
YesMaxTotal (affected versions not specified)
YesMax HD (affected versions not specified)
YesQuattro STB (affected versions not specified)
Description
A vulnerability in the HTTP remote procedure call (RPC) service could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The issue exists because the firmware fails to handle certain XML values passed to the HTTP RPC service. An attacker could exploit this by submitting a malformed request, causing the device to restart and resulting in a DoS condition.
Recommendations
For YesMaxTotal, update to the latest firmware provided by Yes to address the vulnerability.
For YesMax HD, update to the latest firmware provided by Yes to address the vulnerability.
For YesQuattro STB, update to the latest firmware provided by Yes to address the vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Yesmax Hd
Yesmaxtotal
Yesquattro Stb