MEDIUM · 6.5

CVE-2016-9494

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to f...

Vulnerability Description

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to from the basic status web page does not appear to properly parse malformed GET requests. This may lead to a denial of service.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
HughesHn7740S Firmware6.9.0.34
HughesHn7740S-
HughesDw7000 Firmware6.9.0.34
HughesDw7000-
HughesHn7000S Firmware6.9.0.34
HughesHn7000S-
HughesHn7000Sm Firmware6.9.0.34
HughesHn7000Sm-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-9494?

CVE-2016-9494 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to f...

How severe is CVE-2016-9494?

CVE-2016-9494 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-9494?

Check the references section above for vendor advisories and patch information. Affected products include: Hughes Hn7740S Firmware, Hughes Hn7740S, Hughes Dw7000 Firmware, Hughes Dw7000, Hughes Hn7000S Firmware.