CVE-2017-6631 describes a denial-of-service vulnerability in Cisco set-top boxes manufactured for Yes, specifically affecting YesMaxTotal, YesMax HD, and YesQuattro devices. An unauthenticated, remote attacker could exploit this by sending a malformed XML request to the HTTP RPC service, causing the device to restart. Rated 7.5 HIGH (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), this vulnerability has a low attack complexity and high impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and the vendor has released firmware updates to address the issue, requiring no customer action.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:yesmax_hd_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:yesmaxtotal_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:cisco:yesquattro_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.