SNMP Access-Control Bypass in Technicolor Devices
CVE-2017-5135
9.1CRITICAL
What is CVE-2017-5135?
Technicolor devices, particularly the DPC3928SL model, are vulnerable to an SNMP access-control bypass. This vulnerability allows unauthorized access using any SNMP community string, potentially facilitating unauthorized configurations or data access from external sources. The issue may be exacerbated by specific ISP customizations, which could influence device security settings. Additionally, due to the presence of write properties in the Management Information Base (MIB), attackers can leverage this to execute harmful actions, demonstrating the critical need for effective security measures to protect affected devices.
References
EPSS Score
22% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved