Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1020 CNY

100%

CVE-2017-6631

EPSS 0.48% · P65
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-6631

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the firmware of an affected device fails to handle certain XML values that are passed to the HTTP RPC service listening on the local subnet of the device. An attacker could exploit this vulnerability by submitting a malformed request to an affected device. A successful attack could cause the affected device to restart, resulting in a DoS condition. Yes has updated the affected devices with firmware that addresses this vulnerability. Customers are not required to take action. Vulnerable Products: This vulnerability affects YesMaxTotal, YesMax HD, and YesQuattro STB devices. Cisco Bug IDs: CSCvd08812.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
资源管理错误
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco YesMaxTotal、YesMax HD和YesQuattro STB 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco YesMaxTotal、YesMax HD和YesQuattro STB都是美国思科(Cisco)公司的视频信号转换器设备。HTTP remote procedure call (RPC) service是其中的一个远程过程调用服务。 Cisco YesMaxTotal、YesMax HD和YesQuattro STB设备的HTTP RPC service存在拒绝服务,该漏洞源于受影响设备的固件没有处理特定的XML值。远程攻击者可通过提交畸形的请求利用该漏洞造成拒绝服务(设备重启)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Cisco Yes Set-Top Box Cisco Yes Set-Top Box -

II. Public POCs for CVE-2017-6631

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-6631

登录查看更多情报信息。

Same Patch Batch · n/a · 2017-09-07 · 77 CVEs total

CVE-2015-1590kamailio 安全漏洞
CVE-2017-9458Palo Alto Networks PAN-OS 安全漏洞
CVE-2015-3442Soreco Xpert.Line 安全漏洞
CVE-2015-3250Apache Directory LDAP API 信息泄露漏洞
CVE-2016-10405D-Link DIR-600L 安全漏洞
CVE-2017-9834WordPress WatuPRO插件SQL注入漏洞
CVE-2017-9779OCaml compiler 安全漏洞
CVE-2017-14147FiberHome User End Routers Bearing AN1020-25 安全漏洞
CVE-2017-12912MP3Gain 缓冲区错误漏洞
CVE-2017-12911MP3Gain 安全漏洞
CVE-2016-0732Pivotal Cloud Foundry和UAA 权限许可和访问控制问题漏洞
CVE-2017-1502IBM Content Navigator 跨站脚本漏洞
CVE-2017-14181mp4tools aacplusenc 安全漏洞
CVE-2017-1189IBM WebSphere Portal和Web Content Manager 跨站脚本漏洞
CVE-2017-1098IBM Emptoris Supplier Lifecycle Management 跨站脚本漏洞
CVE-2013-7428Joomla! Googlemaps插件安全漏洞
CVE-2017-14195dayrui FineCms 跨站脚本漏洞
CVE-2017-14194dayrui FineCms 跨站脚本漏洞
CVE-2017-14193dayrui FineCms 跨站脚本漏洞
CVE-2017-14192dayrui FineCms 跨站脚本漏洞

Showing top 20 of 77 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2017-6631

No comments yet


Leave a comment