CVE-2017-17749: XSS
Published Mar 24, 2018
·Updated
Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
Affected Software
2 affected components
Bose Soundtouch Android
Bose Soundtouch Iphone Os
Event History
Mar 24, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17749?
CVE-2017-17749 is classified as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-17749?
To mitigate CVE-2017-17749, users should update their Bose SoundTouch devices to the latest firmware version provided by the manufacturer.
3
What devices are affected by CVE-2017-17749?
CVE-2017-17749 affects Bose SoundTouch devices running on Android and iPhone OS platforms.
4
What type of attack can exploit CVE-2017-17749?
CVE-2017-17749 can be exploited through cross-site scripting (XSS) by injecting malicious song data from a music service.
5
Is user interaction required to exploit CVE-2017-17749?
Yes, user interaction is generally required to trigger the XSS vulnerability in CVE-2017-17749 by inducing users to play the crafted song data.