CVE-2017-9488
8.8
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) and DPC3941T (firmware version DPC3941_2.5s3_PROD_sey) devices allows remote attackers to access the web UI by establishing a session to the wan0 WAN IPv6 address and then entering unspecified hardcoded credentials. This wan0 interface cannot be accessed from the public Internet.
Affected (2)
Products: Cisco: Dpc3939 Firmware, Dpc3941t Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version dpc3939-p20-18-v303r20421746-170221a-cmcst |
| Running on/with | Platform Versions |
|---|---|
Cisco Dpc3939 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version dpc3941_2.5s3_prod_sey |
| Running on/with | Platform Versions |
|---|---|
Cisco Dpc3941t | All versions |
References (2)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.