CVE-2017-5042 describes a vulnerability in Google Chrome versions prior to 57.0.2987.98 (Mac, Windows, Linux) and 57.0.2987.108 (Android) where the Cast feature inadvertently sent cookies to sites discovered via SSDP. This flaw allowed an attacker on the same local network segment to initiate connections to arbitrary URLs and intercept any plaintext cookies transmitted. With a CVSS score of 5.7 (Medium), the vulnerability has an adjacent attack vector (AV:A) and high confidentiality impact (C:H), but requires low privileges (PR:L) and no user interaction (UI:N). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 57.0.2987.75CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
<= 57.0.2987.100CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.