Cross-Site Request Forgery Vulnerability in Cisco DPC3939B Firmware by Comcast
CVE-2017-9489
8.8HIGH
Summary
The Cisco DPC3939B firmware, particularly version dpc3939b-v303r204217-150321a-CMCST deployed by Comcast, exhibits a vulnerability that allows unauthorized configuration changes due to Cross-Site Request Forgery (CSRF). An attacker could leverage this flaw to manipulate device settings without user consent, potentially compromising the user's network integrity.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved