First published: Mon Jul 31 2017(Updated: )
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving digital signatures for the firmware.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Motorola Mx011anm Firmware | =mx011an_2.9p6s1_prod_sey | |
Motorola Mx011anm Firmware | ||
Comcast Xfinity XR11 Firmware | ||
Comcast Xfinity XR11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9498 is classified as a critical vulnerability due to its potential to allow unauthorized firmware uploads.
To fix CVE-2017-9498, users should update their devices to the latest firmware version provided by the manufacturer that addresses this vulnerability.
CVE-2017-9498 affects users of Motorola MX011ANM firmware version MX011AN_2.9p6s1_PROD_sey and Comcast Xfinity XR11-20 devices.
CVE-2017-9498 allows a local attacker with root access to upload arbitrary firmware images to affected devices.
While there may not be publicly available exploit code, the vulnerability's nature indicates that it could be exploited by anyone with local access to the device.