Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-9494


Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to from the basic status web page does not appear to properly parse malformed GET requests. This may lead to a denial of service.


Published

2018-07-13T20:29:01.737

Last Modified

2024-11-21T03:01:19.513

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-20
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hughes hn7740s_firmware 6.9.0.34 Yes
Hardware hughes hn7740s - No
Operating System hughes dw7000_firmware 6.9.0.34 Yes
Hardware hughes dw7000 - No
Operating System hughes hn7000s_firmware 6.9.0.34 Yes
Hardware hughes hn7000s - No
Operating System hughes hn7000sm_firmware 6.9.0.34 Yes
Hardware hughes hn7000sm - No

References