CVE-2024-42637

H3C R3010 v100R002L02 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:h3c:r3010_firmware:100r002l02:*:*:*:*:*:*:*
cpe:2.3:h:h3c:r3010:-:*:*:*:*:*:*:*

History

27 May 2025, 16:19

Type Values Removed Values Added
CPE cpe:2.3:h:h3c:r3010:-:*:*:*:*:*:*:*
cpe:2.3:o:h3c:r3010_firmware:100r002l02:*:*:*:*:*:*:*
References () https://palm-vertebra-fe9.notion.site/H3C-R3010V100R002L02-was-discovered-to-contain-a-hardcoded-d3212602f84443d4b17e3247b3e6b129 - () https://palm-vertebra-fe9.notion.site/H3C-R3010V100R002L02-was-discovered-to-contain-a-hardcoded-d3212602f84443d4b17e3247b3e6b129 - Exploit, Third Party Advisory
References () https://www.h3c.com/cn/d_202308/1907175_30005_0.htm - () https://www.h3c.com/cn/d_202308/1907175_30005_0.htm - Product
First Time H3c
H3c r3010
H3c r3010 Firmware

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) Se descubrió que H3C R3010 v100R002L02 contenía una vulnerabilidad de contraseña codificada en /etc/shadow, que permite a los atacantes iniciar sesión como superusuario.

16 Aug 2024, 21:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-798

16 Aug 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 18:15

Updated : 2025-05-27 16:19


NVD link : CVE-2024-42637

Mitre link : CVE-2024-42637

CVE.ORG link : CVE-2024-42637


JSON object : View

Products Affected

h3c

  • r3010_firmware
  • r3010
CWE
CWE-798

Use of Hard-coded Credentials