CVE-2017-13717 Vulnerability Details

  /     /     /  

CVE-2017-13717 Metadata Quick Info

CVE Published: 10/06/2019 | CVE Updated: 05/08/2024 | CVE Year: 2017
Source: mitre | Vendor: n/a | Product: n/a
Status : PUBLISHED

CVE-2017-13717 Description

Starry Station (aka Starry Router) sets the Access-Control-Allow-Origin header to "*". This allows any hosted file on any domain to make calls to the device\'s webserver and brute force the credentials and pull any information that is stored on the device. In this case, a user\'s Wi-Fi credentials are stored in clear text on the device and can be pulled easily.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: n/a
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).