CVE-2017-9521: Critical severity Cisco Dpc3939 Firmware vulnerability
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST); Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST); Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST); Cisco DPC3941T (firmware version DPC39412.5s3PRODsey); and Arris TG1682G (eMTA&DOCSIS version 10.0.132.SIP.PC20.CT, software version TG16822.2p7s2PRODsey) devices allows remote attackers to execute arbitrary code via a specific (but unstated) exposed service. NOTE: the scope of this CVE does NOT include the concept of "Unnecessary Services" in general; the scope is only a single service that is unnecessarily exposed, leading to remote code execution. The details of that service might be disclosed at a later date.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9521?
CVE-2017-9521 is classified as a high-severity vulnerability due to its potential for exploitation.
How do I fix CVE-2017-9521?
To mitigate CVE-2017-9521, upgrade the firmware on affected Cisco and Commscope device models to the latest patched versions.
Which devices are affected by CVE-2017-9521?
CVE-2017-9521 affects Cisco DPC3939, DPC3939B, DPC3941T, and certain Commscope Arris TG1682G firmware versions.
What could happen if CVE-2017-9521 is exploited?
Exploitation of CVE-2017-9521 could lead to unauthorized access or control over affected Cisco and Commscope devices.
Is there a workaround for CVE-2017-9521?
Until a firmware update is applied, limiting access to the device’s management interfaces can serve as a temporary workaround for CVE-2017-9521.