CVE Feed

    Dashboard / CVE / CVE-2017-17704

    CVE-2017-17704

    A door-unlocking issue was discovered on Software House iStar Ultra devices through 6.5.2.20569 when used in conjunction with the IP-ACM Ethernet Door Module. The communications between the IP-ACM and the iStar Ultra is encrypted using a fixed AES key and IV. Each message is encrypted in CBC mode and restarts with the fixed IV, leading to replay attacks of entire messages. There is no authentication of messages beyond the use of the fixed AES key, so message forgery is also possible.

    Published:Dec 31, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 31, 2017
    EPSS Score:0.00155
    CVSS Score:7.4

    Affected Products

    Vendor
    Swhouse
    Product
    Istar Ultra
    Vendor
    Swhouse
    Product
    Istar Ultra Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High