First published: Fri Aug 16 2024(Updated: )
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
H3C Magic B1ST Firmware | =100r012 | |
H3C Magic B1STW |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42638 is considered a critical severity vulnerability due to its potential to allow unauthorized root access.
To fix CVE-2024-42638, update the H3C Magic B1ST firmware to the latest version without hardcoded passwords.
The risks associated with CVE-2024-42638 include unauthorized access to the system, data breaches, and potential system compromise.
CVE-2024-42638 affects H3C Magic B1ST firmware version 100R012.
Yes, CVE-2024-42638 can be exploited remotely due to the hardcoded password vulnerability.