CVE-2024-42639: Critical severity h3c gr1100-p firmware vulnerability
Published Aug 16, 2024
·Updated
H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
Affected Software
3 affected components
H3C GR1100-P
All of the following
H3C Gr1100-p Firmware=100r009
H3C GR1100-P
Event History
Aug 16, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42639?
CVE-2024-42639 is classified as a critical vulnerability due to the presence of a hardcoded password that allows unauthorized root access.
2
How do I fix CVE-2024-42639?
To remediate CVE-2024-42639, it is essential to update the H3C GR1100-P firmware to a version that does not utilize hardcoded passwords.
3
What are the risks associated with CVE-2024-42639?
The risks of CVE-2024-42639 include potential unauthorized access to the device, allowing attackers to execute commands with root privileges.
4
Which devices are affected by CVE-2024-42639?
CVE-2024-42639 affects the H3C GR1100-P device running the v100R009 firmware.
5
Can CVE-2024-42639 be exploited remotely?
Yes, CVE-2024-42639 can be exploited remotely due to the hardcoded password allowing attackers to log in as root from any location.