CVE-2017-6631
Summary
| CVE | CVE-2017-6631 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-09-07 21:29:00 UTC |
| Updated | 2019-10-09 23:28:00 UTC |
| Description | A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the firmware of an affected device fails to handle certain XML values that are passed to the HTTP RPC service listening on the local subnet of the device. An attacker could exploit this vulnerability by submitting a malformed request to an affected device. A successful attack could cause the affected device to restart, resulting in a DoS condition. Yes has updated the affected devices with firmware that addresses this vulnerability. Customers are not required to take action. Vulnerable Products: This vulnerability affects YesMaxTotal, YesMax HD, and YesQuattro STB devices. Cisco Bug IDs: CSCvd08812. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cisco | Yesmaxtotal | - | All | All | All |
| Hardware | Cisco | Yesmaxtotal | - | All | All | All |
| Operating System | Cisco | Yesmaxtotal Firmware | - | All | All | All |
| Operating System | Cisco | Yesmaxtotal Firmware | - | All | All | All |
| Hardware | Cisco | Yesmax Hd | - | All | All | All |
| Hardware | Cisco | Yesmax Hd | - | All | All | All |
| Operating System | Cisco | Yesmax Hd Firmware | - | All | All | All |
| Operating System | Cisco | Yesmax Hd Firmware | - | All | All | All |
| Hardware | Cisco | Yesquattro | - | All | All | All |
| Hardware | Cisco | Yesquattro | - | All | All | All |
| Operating System | Cisco | Yesquattro Firmware | - | All | All | All |
| Operating System | Cisco | Yesquattro Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Multiple Cisco Products CVE-2017-6631 Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Cisco Yes Set-Top Box Denial of Service vulnerability | CONFIRM | tools.cisco.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.