Vulnerability Description
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and use a shell.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU93546510/
- https://kddi-tech.com/contents/appendix_L2_06.html#20304f4c-af1b-49fd-c3b5-8d1f5
- https://jvn.jp/en/vu/JVNVU93546510/
- https://www.au.com/support/service/internet/guide/modem/bl1500hm/firmware/
FAQ
What is CVE-2024-21865?
CVE-2024-21865 is a vulnerability with a CVSS score of 6.5 (MEDIUM). HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network-adjacent unauthenticated attacker may connect to the product via SSH and use a shell.
How severe is CVE-2024-21865?
CVE-2024-21865 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-21865?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.