Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-9497


Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does not require authentication. An unauthenticated remote user can access many administrative commands via this interface, including rebooting the modem.


Published

2018-07-13T20:29:01.910

Last Modified

2024-11-21T03:01:19.907

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

10.0

Weaknesses
  • Type: Secondary
    CWE-288
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System hughes hn7740s_firmware 6.9.0.34 Yes
Hardware hughes hn7740s - No
Operating System hughes dw7000_firmware 6.9.0.34 Yes
Hardware hughes dw7000 - No
Operating System hughes hn7000s_firmware 6.9.0.34 Yes
Hardware hughes hn7000s - No
Operating System hughes hn7000sm_firmware 6.9.0.34 Yes
Hardware hughes hn7000sm - No

References