CVE-2016-9494
6.5
Vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.8 / Impact: 3.6
Source: NVD
Description
Hughes high-performance broadband satellite modems, models HN7740S DW7000 HN7000S/SM, are potentially vulnerable to improper input validation. The device's advanced status web page that is linked to from the basic status web page does not appear to properly parse malformed GET requests. This may lead to a denial of service.
Affected (4)
Products: Hughes: Hn7740s Firmware, Dw7000 Firmware, Hn7000s Firmware, Hn7000sm Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.9.0.34 |
| Running on/with | Platform Versions |
|---|---|
Hughes Hn7740s | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.9.0.34 |
| Running on/with | Platform Versions |
|---|---|
Hughes Dw7000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.9.0.34 |
| Running on/with | Platform Versions |
|---|---|
Hughes Hn7000s | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.9.0.34 |
| Running on/with | Platform Versions |
|---|---|
Hughes Hn7000sm | All versions |
References (4)
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Timeline
No history available yet.