First published: Mon Dec 18 2017(Updated: )
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
BrightSign OS | <=6.2.63 | |
BrightSign 4K242 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17737 is classified as a high-severity vulnerability due to its potential for XSS attacks.
To fix CVE-2017-17737, upgrade the BrightSign 4K242 firmware to version 6.2.64 or higher.
CVE-2017-17737 can be exploited for Cross-Site Scripting (XSS) attacks targeting web management interfaces.
CVE-2017-17737 affects BrightSign 4K242 firmware version 6.2.63 and below.
CVE-2017-17737 specifically impacts the BrightSign 4K242 model and is not reported to affect other models.