Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-11502. PoCs published by SecuriTeam.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file disclosure vulnerability in Cisco DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway via a directory traversal attack on TCP/4321. The PoC retrieves the /etc/passwd file by sending a crafted HTTP GET request.
Description
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.
Exploits (1)
This exploit demonstrates an arbitrary file disclosure vulnerability in Cisco DPC3928AD DOCSIS 3.0 2-PORT Voice Gateway via a directory traversal attack on TCP/4321. The PoC retrieves the /etc/passwd file by sending a crafted HTTP GET request.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H