CVE-2017-10793
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an sbdc.ha WAN TCP service on port 61001 with the bdctest account and the bdctest password, which allows…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an sbdc.ha WAN TCP service on port 61001 with the bdctest account and the bdctest password, which allows remote attackers to obtain sensitive information (such as the Wi-Fi password) by leveraging knowledge of a hardware identifier, related to the Bulk Data Collection (BDC) mechanism defined in Broadband Forum technical reports.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.78% probability · 86th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- att/u-verse firmware
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/100585Third Party Advisory, VDB Entry
- https://threatpost.com/bugs-in-arris-modems-distributed-by-att-vulnerable-to-trivial-attacks/127753/Third Party Advisory
- https://www.nomotion.net/blog/sharknatto/Exploit, Mitigation, Technical Description, Third Party Advisory
- http://www.securityfocus.com/bid/100585Third Party Advisory, VDB Entry
- https://threatpost.com/bugs-in-arris-modems-distributed-by-att-vulnerable-to-trivial-attacks/127753/Third Party Advisory
- https://www.nomotion.net/blog/sharknatto/Exploit, Mitigation, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.