CVE-2017-6631 (CNNVD-201709-221)
中文标题:
Cisco YesMaxTotal、YesMax HD和YesQuattro STB 安全漏洞
英文标题:
A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manuf...
漏洞描述
中文描述:
Cisco YesMaxTotal、YesMax HD和YesQuattro STB都是美国思科(Cisco)公司的视频信号转换器设备。HTTP remote procedure call (RPC) service是其中的一个远程过程调用服务。 Cisco YesMaxTotal、YesMax HD和YesQuattro STB设备的HTTP RPC service存在拒绝服务,该漏洞源于受影响设备的固件没有处理特定的XML值。远程攻击者可通过提交畸形的请求利用该漏洞造成拒绝服务(设备重启)。
英文描述:
A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the firmware of an affected device fails to handle certain XML values that are passed to the HTTP RPC service listening on the local subnet of the device. An attacker could exploit this vulnerability by submitting a malformed request to an affected device. A successful attack could cause the affected device to restart, resulting in a DoS condition. Yes has updated the affected devices with firmware that addresses this vulnerability. Customers are not required to take action. Vulnerable Products: This vulnerability affects YesMaxTotal, YesMax HD, and YesQuattro STB devices. Cisco Bug IDs: CSCvd08812.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| cisco | yesmax_hd_firmware | - | - | - |
cpe:2.3:o:cisco:yesmax_hd_firmware:-:*:*:*:*:*:*:*
|
| cisco | yesmaxtotal_firmware | - | - | - |
cpe:2.3:o:cisco:yesmaxtotal_firmware:-:*:*:*:*:*:*:*
|
| cisco | yesquattro_firmware | - | - | - |
cpe:2.3:o:cisco:yesquattro_firmware:-:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2017-6631 |
2025-11-11 15:19:31 | 2025-11-11 07:34:50 |
| NVD | nvd_CVE-2017-6631 |
2025-11-11 14:55:31 | 2025-11-11 07:43:28 |
| CNNVD | cnnvd_CNNVD-201709-221 |
2025-11-11 15:09:53 | 2025-11-11 07:53:17 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201709-221
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- cvss_version: NOT_EXTRACTED -> 3.0
- affected_products_count: 0 -> 3
- data_sources: ['cve'] -> ['cve', 'nvd']