PT-2018-5087 · Hughes · Hn7740S+2
Publicado
2018-07-13
·
Atualizado
2019-10-09
·
CVE-2016-9497
CVSS v3.1
8.8
Alta
| Vetor | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM
Description
The issue allows for an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does not require authentication. An unauthenticated remote user can access many administrative commands via this interface, including rebooting the modem.
Recommendations
For Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, consider restricting access to port 1953 to minimize the risk of exploitation. As a temporary workaround, limit the use of telnet on this port until a more secure configuration or patch is available.
Correção
Authentication Bypass Using an Alternate Path or Channel
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dw7000
Hn7000S/Sm
Hn7740S