Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
Fixes

Solution

Hughes Network Systems has patched the vulnerabilities, which requires no action by the user. Any questions or concerns should be directed to Hughes Network Systems customer support https://www.hughes.com/who-we-are/contact-us .


Workaround

No workaround given by the vendor.

History

Fri, 04 Oct 2024 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Echostar
Echostar fusion
Echostar hughes Wl3000
CPEs cpe:2.3:a:echostar:fusion:*:*:*:*:*:*:*:*
cpe:2.3:h:echostar:hughes_wl3000:-:*:*:*:*:*:*:*
Vendors & Products Echostar
Echostar fusion
Echostar hughes Wl3000

Fri, 06 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 22:45:00 +0000

Type Values Removed Values Added
Description Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.
Title Hughes Network Systems Insufficiently Protected Credentials
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 4.1, 'vector': 'CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-06T13:26:53.933Z

Reserved: 2024-08-05T16:23:44.808Z

Link: CVE-2024-39278

cve-icon Vulnrichment

Updated: 2024-09-06T13:26:50.434Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-05T23:15:12.233

Modified: 2024-10-04T14:36:35.340

Link: CVE-2024-39278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.