HIGH · 8.8

CVE-2016-9497

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible ...

Vulnerability Description

Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible via telnet and does not require authentication. An unauthenticated remote user can access many administrative commands via this interface, including rebooting the modem.

CVSS Score

8.8

HIGH

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HughesHn7740S Firmware6.9.0.34
HughesHn7740S-
HughesDw7000 Firmware6.9.0.34
HughesDw7000-
HughesHn7000S Firmware6.9.0.34
HughesHn7000S-
HughesHn7000Sm Firmware6.9.0.34
HughesHn7000Sm-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-9497?

CVE-2016-9497 is a vulnerability with a CVSS score of 8.8 (HIGH). Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, is vulnerable to an authentication bypass using an alternate path or channel. By default, port 1953 is accessible ...

How severe is CVE-2016-9497?

CVE-2016-9497 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-9497?

Check the references section above for vendor advisories and patch information. Affected products include: Hughes Hn7740S Firmware, Hughes Hn7740S, Hughes Dw7000 Firmware, Hughes Dw7000, Hughes Hn7000S Firmware.