CVE-2024-38902: Critical severity h3c magic r230 vulnerability
H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38902?
The severity of CVE-2024-38902 is classified as critical due to the presence of a hardcoded password vulnerability that allows attackers to gain root access.
How do I fix CVE-2024-38902?
To fix CVE-2024-38902, it is recommended to update the firmware of the H3C Magic R230 to the latest version provided by the vendor.
What impact does CVE-2024-38902 have on my system?
CVE-2024-38902 can lead to unauthorized root access, potentially allowing attackers to gain full control over the affected device.
Which version of H3C Magic R230 is affected by CVE-2024-38902?
CVE-2024-38902 affects the H3C Magic R230 V100R002 version specifically.
Is there a workaround for CVE-2024-38902 if I cannot update immediately?
While an immediate update is the best solution for CVE-2024-38902, changing any configurations that rely on default credentials is a temporary measure to mitigate the risk.