Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2017-8329

6.4 · MEDIUM
Published Jun 18, 2019 securifi CWE-119 EPSS 2.01% (79th pctl)

Overview

CVE-2017-8329 is a medium-severity vulnerability affecting securifi almond_2015_firmware. It was published on June 18, 2019 and has a CVSS 3.0 base score of 6.4 (MEDIUM).

This vulnerability has a CVSS 3.0 base score of 6.4, rated MEDIUM. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of setting a name for the wireless network. These values are stored by the device in NVRAM (Non-volatile RAM). It seems that the POST parameters passed in this request to set up names on the device do not have a string length check on them. This allows an attacker to send a large payload in the "mssid_1" POST parameter. The device also allows a user to view the name of the Wifi Network set by the user. While processing this request, the device calls a function at address 0x00412CE4 (routerSummary) in the binary "webServer" located in Almond folder, which retrieves the value set earlier by "mssid_1" parameter as SSID2 and this value then results in overflowing the stack set up for this function and allows an attacker to control $ra register value on the stack which allows an attacker to control the device by executing a payload of an attacker

Remediation

Check the references section for vendor advisories and patches from securifi. Update almond_2015_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status

Frequently Asked Questions

What is CVE-2017-8329?

CVE-2017-8329 is a medium-severity vulnerability affecting securifi almond_2015_firmware. It was published on June 18, 2019 and has a CVSS 3.0 base score of 6.4 (MEDIUM).

How severe is CVE-2017-8329?

This vulnerability has a CVSS 3.0 base score of 6.4, rated MEDIUM. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2017-8329?

Check the references section for vendor advisories and patches from securifi. Update almond_2015_firmware to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2017-8329?

CyberStrike's AI-powered security agents can automatically detect CVE-2017-8329 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.