CVE-2017-16836: XSS
Published Nov 16, 2017
·Updated
Arris TG1682G devices with Comcast TG16822.0s7PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via the actionHandler/ajaxmanagedservices.php service parameter.
Affected Software
2 affected components
CommScope Arris Tg1682g Firmware=10.0.59.sip.pc20.ct
CommScope Arris Tg1682g
Event History
Nov 16, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-16836.
2
What is the severity of CVE-2017-16836?
CVE-2017-16836 has a severity rating of 6.1 (Medium).
3
What is the affected software for CVE-2017-16836?
The affected software for CVE-2017-16836 is Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software.
4
How does CVE-2017-16836 work?
CVE-2017-16836 allows Unauthenticated Stored XSS via the actionHandler/ajax_managed_services.php service parameter.
5
Is there a fix available for CVE-2017-16836?
Currently, there is no known fix available for CVE-2017-16836. It is recommended to contact the vendor for more information.