Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14116

Опубликовано: 03 сент. 2017
Источник: nvd
CVSS3: 8.1
CVSS2: 9.3
EPSS Низкий

Описание

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote attackers to obtain root privileges by establishing a session on port 49955 and then installing new software, such as BusyBox with "nc -l" support.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:att:u-verse_firmware:9.2.2h0d83:*:*:*:*:*:*:*
cpe:2.3:h:commscope:arris_nvg599:-:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.04024
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-798

Связанные уязвимости

CVSS3: 8.1
github
больше 3 лет назад

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG599 device, when IP Passthrough mode is not used, configures WAN access to a caserver https service with the tech account and an empty password, which allows remote attackers to obtain root privileges by establishing a session on port 49955 and then installing new software, such as BusyBox with "nc -l" support.

EPSS

Процентиль: 88%
0.04024
Низкий

8.1 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-798