CVE-2017-9489: CSRF
Published Jul 31, 2017
·Updated
The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF.
Affected Software
5 affected components
Cisco Dpc3939b Firmware=dpc3939b-v303r204217-150321a-cmcst
Cisco DPC3939B
CommScope Arris Tg1682g Firmware=10.0.132.sip.pc20.ct
CommScope Arris Tg1682g Firmware=tg1682_2.2p7s2_prod_sey
CommScope Arris Tg1682g
Event History
Jul 31, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9489?
The severity of CVE-2017-9489 is classified as high with a CVSS score of 8.8.
2
How do I fix CVE-2017-9489?
To fix CVE-2017-9489, ensure your Cisco DPC3939B firmware is updated to a version that mitigates this vulnerability.
3
What devices are affected by CVE-2017-9489?
CVE-2017-9489 affects Cisco DPC3939B devices running firmware version dpc3939b-v303r204217-150321a-CMCST.
4
What type of vulnerability is CVE-2017-9489?
CVE-2017-9489 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
What can happen if CVE-2017-9489 is exploited?
If exploited, CVE-2017-9489 can allow an attacker to make unauthorized configuration changes on the affected devices.