CVE-2024-42637: Critical severity h3c magic r3010 vulnerability
Published Aug 16, 2024
·Updated
H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
Affected Software
3 affected components
H3C R3010
All of the following
H3C R3010 Firmware=100r002l02
H3C R3010
Event History
Aug 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-42637?
CVE-2024-42637 has been classified as a critical vulnerability due to the presence of a hardcoded password that allows for root access.
2
How do I fix CVE-2024-42637?
To mitigate CVE-2024-42637, update the H3C R3010 to the latest firmware that removes the hardcoded password.
3
What systems are affected by CVE-2024-42637?
CVE-2024-42637 specifically affects the H3C R3010 version v100R002L02.
4
Can CVE-2024-42637 be exploited remotely?
Yes, CVE-2024-42637 can be exploited remotely since it allows attackers to log in as root without local access.
5
What is the potential impact of CVE-2024-42637?
The potential impact of CVE-2024-42637 includes full system compromise, unauthorized access, and the ability to manipulate or steal sensitive data.