← Back

CVE-2017-9491

nvd nist
Published: Jul 31, 2017Modified: May 13, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC3941_2.5s3_PROD_sey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG1682_2.2p7s2_PROD_sey) devices does not set the secure flag for cookies in an https session to an administration application, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.

Affected (6)

3 products
Dpc3939 Firmware
Dpc3939b Firmware
Dpc3941t Firmware
1 product
Arris Tg1682g Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version dpc3939-p20-18-v303r20421733-160420a-cmcst
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version dpc3939-p20-18-v303r20421746-170221a-cmcst
Running on/withPlatform Versions
Cisco
Dpc3939
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version dpc3939b-v303r204217-150321a-cmcst
Running on/withPlatform Versions
Cisco
Dpc3939b
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version dpc3941_2.5s3_prod_sey
Running on/withPlatform Versions
Cisco
Dpc3941t
All versions
Configuration E
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Commscope
Version 10.0.132.sip.pc20.ct
Version tg1682_2.2p7s2_prod_sey
Running on/withPlatform Versions
Commscope
Arris Tg1682g
All versions

Timeline

No history available yet.