PT-2017-18952 · Cisco · Cisco Dpc3939
Chris Grayson
+2
·
Published
2017-07-31
·
Updated
2017-08-02
·
CVE-2017-9480
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST
Description
The issue allows local users with command access to read arbitrary files via UPnP access to the
/var/IGD/ directory. This can be exploited by users who have gained command access as a result of previous exploitation.Recommendations
For Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST, consider restricting access to the
/var/IGD/ directory to minimize the risk of exploitation. As a temporary workaround, disabling UPnP access until a patch is available can help mitigate the issue.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Dpc3939