PT-2017-18988 · Cisco+1 · Cisco Dpc3939B+3

Chris Grayson

+2

·

Published

2017-07-31

·

Updated

2021-09-13

·

CVE-2017-9521

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco DPC3939 version dpc3939-P20-18-v303r20421733-160420a-CMCST Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST Cisco DPC3939B version dpc3939b-v303r204217-150321a-CMCST Cisco DPC3941T version DPC3941 2.5s3 PROD sey Arris TG1682G version 10.0.132.SIP.PC20.CT, software version TG1682 2.2p7s2 PROD sey
Description The issue allows remote attackers to execute arbitrary code via a specific exposed service on the affected devices. The details of the exposed service might be disclosed at a later date.
Recommendations For Cisco DPC3939 version dpc3939-P20-18-v303r20421733-160420a-CMCST, consider disabling the exposed service until a patch is available. For Cisco DPC3939 version dpc3939-P20-18-v303r20421746-170221a-CMCST, consider disabling the exposed service until a patch is available. For Cisco DPC3939B version dpc3939b-v303r204217-150321a-CMCST, consider disabling the exposed service until a patch is available. For Cisco DPC3941T version DPC3941 2.5s3 PROD sey, consider disabling the exposed service until a patch is available. For Arris TG1682G version 10.0.132.SIP.PC20.CT, software version TG1682 2.2p7s2 PROD sey, consider disabling the exposed service until a patch is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-9521

Affected Products

Arris Tg1682G
Cisco Dpc3939
Cisco Dpc3939B
Cisco Dpc3941T