CVE-2017-14117 describes an unauthenticated proxy service vulnerability in AT&T U-verse firmware versions 9.2.2h0d83 for Arris NVG589 and NVG599 devices, specifically when not in IP Passthrough mode. This flaw allows remote attackers to establish arbitrary TCP connections to internal network hosts. The vulnerability has a CVSS score of 5.9 (Medium) due to its network attack vector and high integrity impact, despite requiring high attack complexity. While there is no evidence of active exploitation or community discussion, a Metasploit module exists, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.2.2h0d83CPE matchmatch criteria | cpe:2.3:o:att:u-verse_firmware:9.2.2h0d83:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.