PT-2017-3500 · Valve · Valve Steam Link
Published
2017-12-22
·
Updated
2019-10-03
·
CVE-2017-17877
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Valve Steam Link build 643
Description
The issue is related to inadequate access control in the Valve Steam Link device. When the SSH daemon is enabled for local development, the device becomes publicly accessible via IPv6 TCP port 22 over the internet by default. This makes it easier for remote attackers to gain access by guessing 24 bits of the MAC address and attempting a root login.
Recommendations
For Valve Steam Link build 643, consider disabling the SSH daemon when not in use for local development to prevent unauthorized access. Restrict access to IPv6 TCP port 22 to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Valve Steam Link