PT-2017-3500 · Valve · Valve Steam Link

Published

2017-12-22

·

Updated

2019-10-03

·

CVE-2017-17877

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Valve Steam Link build 643
Description The issue is related to inadequate access control in the Valve Steam Link device. When the SSH daemon is enabled for local development, the device becomes publicly accessible via IPv6 TCP port 22 over the internet by default. This makes it easier for remote attackers to gain access by guessing 24 bits of the MAC address and attempting a root login.
Recommendations For Valve Steam Link build 643, consider disabling the SSH daemon when not in use for local development to prevent unauthorized access. Restrict access to IPv6 TCP port 22 to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00328
CVE-2017-17877

Affected Products

Valve Steam Link