CVE-2017-17877

UnknownEPSS 4.10%

Last modified

CVE-2017-17877 is a vulnerability of currently unknown severity. An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. EPSS estimates a 4.10% chance of exploitation in the next 30 days.

Description

An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.

Metrics

EPSS Probability
4.10%

89.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
ValvesoftwareSteam Link Firmware< 644

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-17877?
An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.
How severe is CVE-2017-17877?
Severity scoring for CVE-2017-17877 is pending analysis. The EPSS model estimates a 4.10% probability of exploitation in the next 30 days.
How do I fix CVE-2017-17877?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-17877?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST