CVE Feed

    Dashboard / CVE / CVE-2017-17877

    CVE-2017-17877

    An issue was discovered in Valve Steam Link build 643. When the SSH daemon is enabled for local development, the device is publicly available via IPv6 TCP port 22 over the internet (with stateless address autoconfiguration) by default, which makes it easier for remote attackers to obtain access by guessing 24 bits of the MAC address and attempting a root login. This can be exploited in conjunction with CVE-2017-17878.

    Published:Dec 24, 2017
    Last Modified:Apr 20, 2025
    EPS:Dec 24, 2017
    EPSS Score:0.01273
    CVSS Score:9.8

    Affected Products

    Vendor
    Valvesoftware
    Product
    Steam Link
    Vendor
    Valvesoftware
    Product
    Steam Link Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High