PatchSiren cyber security CVE debrief
CVE-2017-6445 Openelec CVE debrief
CVE-2017-6445 describes a weakness in OpenELEC's auto-update feature where update traffic was neither encrypted nor signed. According to the CVE record, a man-in-the-middle attacker could tamper with update packages and gain remote root access.
- Vendor
- Openelec
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-05
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-05
- Advisory updated
- 2026-05-13
Who should care
Anyone operating OpenELEC systems that rely on automatic updates, especially in environments where update traffic could be intercepted or altered. Administrators should treat this as a high-risk remote compromise issue because the update path itself is part of the attack surface.
Technical summary
The supplied CVE description says OpenELEC 6.0.3, 7.0.1, and 8.0.4 used auto-update downloads without encrypted connections or signed updates. That combination allows an attacker in a man-in-the-middle position to modify the delivered update package before installation, which can lead to root-level compromise. NVD maps the issue to CWE-311 and CWE-347 and rates it CVSS v3.0 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Defensive priority
High
Recommended defensive actions
- Restrict or disable automatic update flows until update transport is authenticated and update packages are integrity-checked.
- Verify that all update artifacts are signed and that signature validation is enforced before installation.
- Move update retrieval onto trusted networks or protected channels where interception risk is reduced.
- Check deployed OpenELEC versions against the affected releases named in the CVE description: 6.0.3, 7.0.1, and 8.0.4.
- Monitor the official CVE/NVD record and linked third-party advisories for any vendor guidance or remediation notes.
Evidence notes
This debrief is based on the CVE description and the official NVD record supplied in the corpus. The record states that OpenELEC's auto-update feature used neither encrypted connections nor signed updates, enabling man-in-the-middle manipulation of update packages and remote root access. NVD also lists CWE-311 and CWE-347 and a CVSS v3.0 vector of AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. The supplied references include an official CVE record, the NVD detail page, a SecurityFocus BID, and two third-party technical advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6445 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6445
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6445 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6445
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://tech.feedyourhead.at/content/openelec-cve-2017-6445-revisited
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://tech.feedyourhead.at/content/openelec-remote-code-execution-vulnerability-through-man-in-the-middle
[email protected] - Exploit, Technical Description, Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.