Remote Code Execution Vulnerability in Motorola and Xfinity Devices
CVE-2017-9498

5.5MEDIUM

Key Information:

Vendor
Motorola
Vendor
CVE Published:
31 July 2017

Summary

Local users with root access on Comcast firmware-enabled devices, specifically the Motorola MX011ANM and Xfinity XR11-20 Voice Remote, can exploit a serious vulnerability that permits the upload of arbitrary firmware images. This significant oversight occurs due to the lack of digital signatures for firmware protection. Consequently, an unauthorized user could potentially compromise device functionality and security by uploading malicious firmware, leading to unauthorized control and data access.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.