CVE-2017-9497: Input Validation
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN2.9p6s1PRODsey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Inspector route.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9497?
CVE-2017-9497 is considered a critical vulnerability due to its ability to allow arbitrary command execution as root.
How do I fix CVE-2017-9497?
To fix CVE-2017-9497, update the firmware of the Motorola MX011ANM devices to a version that addresses this vulnerability.
Who is affected by CVE-2017-9497?
CVE-2017-9497 affects devices running Comcast firmware on Motorola MX011ANM with version MX011AN_2.9p6s1_PROD_sey.
What can an attacker do with CVE-2017-9497?
An attacker can execute arbitrary commands as root by accessing the diagnostics menu on the vulnerable set-top box.
Is CVE-2017-9497 a remote vulnerability?
No, CVE-2017-9497 requires physical proximity to the device to exploit the vulnerability.