CVE-2017-17877
When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.10%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.10% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- valvesoftware/steam link firmware
- Source
- cve@mitre.org
References
- https://blogger.davidmanouchehri.com/2017/12/steam-link-security-remotely-insecure.htmlIssue Tracking, Third Party Advisory
- https://github.com/ValveSoftware/steamlink-sdk#ssh-accessIssue Tracking, Third Party Advisory
- https://github.com/ValveSoftware/steamlink-sdk/issues/119Issue Tracking, Third Party Advisory
- https://blogger.davidmanouchehri.com/2017/12/steam-link-security-remotely-insecure.htmlIssue Tracking, Third Party Advisory
- https://github.com/ValveSoftware/steamlink-sdk#ssh-accessIssue Tracking, Third Party Advisory
- https://github.com/ValveSoftware/steamlink-sdk/issues/119Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.