PT-2018-5087 · Hughes · Hn7740S+2

Published

2018-07-13

·

Updated

2019-10-09

·

CVE-2016-9497

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM
Description The issue allows for an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does not require authentication. An unauthenticated remote user can access many administrative commands via this interface, including rebooting the modem.
Recommendations For Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, consider restricting access to port 1953 to minimize the risk of exploitation. As a temporary workaround, limit the use of telnet on this port until a more secure configuration or patch is available.

Fix

Authentication Bypass Using an Alternate Path or Channel

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9497

Affected Products

Dw7000
Hn7000S/Sm
Hn7740S