SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5042

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe…

MEDIUM 5.7EPSS 0.36%

Does this matter?

Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.

Description

Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to sites discovered via SSDP, which allowed an attacker on the local network segment to initiate connections to arbitrary URLs and observe any plaintext cookies sent.

CVSS 3.1
5.7 MEDIUMCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.36% probability · 30th percentile
CISA KEV
Not listed
Weakness
CWE-311
Affected
google/chrome · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · debian/debian linux
Source
chrome-cve-admin@google.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.