CVE-2017-9491: Infoleak
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC39412.5s3PRODsey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG16822.2p7s2PRODsey) devices does not set the secure flag for cookies in an https session to an administration application, which makes it easier for remote attackers to capture these cookies by intercepting their transmission within an http session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9491?
CVE-2017-9491 has a severity rating that indicates it poses a risk due to improper cookie handling.
How do I fix CVE-2017-9491?
To fix CVE-2017-9491, upgrade the firmware versions of affected devices to the latest available updates.
Which devices are impacted by CVE-2017-9491?
CVE-2017-9491 affects Cisco DPC3939, Cisco DPC3939B, and Cisco DPC3941T with specific firmware versions.
What is the impact of CVE-2017-9491 on network security?
CVE-2017-9491 can lead to potential security risks such as unauthorized access or session hijacking due to improper cookie flags.
Is CVE-2017-9491 a local or remote vulnerability?
CVE-2017-9491 is considered a remote vulnerability that can be exploited over the network.