PT-2017-18952 · Cisco · Cisco Dpc3939

Chris Grayson

+2

·

Published

2017-07-31

·

Updated

2017-08-02

·

CVE-2017-9480

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST
Description The issue allows local users with command access to read arbitrary files via UPnP access to the /var/IGD/ directory. This can be exploited by users who have gained command access as a result of previous exploitation.
Recommendations For Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST, consider restricting access to the /var/IGD/ directory to minimize the risk of exploitation. As a temporary workaround, disabling UPnP access until a patch is available can help mitigate the issue.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-9480

Affected Products

Cisco Dpc3939