Remote Code Execution Vulnerability in Motorola and Xfinity Devices
CVE-2017-9498
5.5MEDIUM
Summary
Local users with root access on Comcast firmware-enabled devices, specifically the Motorola MX011ANM and Xfinity XR11-20 Voice Remote, can exploit a serious vulnerability that permits the upload of arbitrary firmware images. This significant oversight occurs due to the lack of digital signatures for firmware protection. Consequently, an unauthorized user could potentially compromise device functionality and security by uploading malicious firmware, leading to unauthorized control and data access.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved