CVE-2024-42639

H3C GR1100-P v100R009 was discovered to use a hardcoded password in /etc/shadow, which allows attackers to log in as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:h3c:gr1100-p_firmware:100r009:*:*:*:*:*:*:*
cpe:2.3:h:h3c:gr1100-p:-:*:*:*:*:*:*:*

History

27 May 2025, 17:52

Type Values Removed Values Added
First Time H3c gr1100-p Firmware
H3c
H3c gr1100-p
CPE cpe:2.3:o:h3c:gr1100-p_firmware:100r009:*:*:*:*:*:*:*
cpe:2.3:h:h3c:gr1100-p:-:*:*:*:*:*:*:*
References () https://palm-vertebra-fe9.notion.site/H3C-GR1100-PV100R009-was-discovered-to-contain-a-hardcoded-824141daa44f4c52a914860c6e4a7684 - () https://palm-vertebra-fe9.notion.site/H3C-GR1100-PV100R009-was-discovered-to-contain-a-hardcoded-824141daa44f4c52a914860c6e4a7684 - Exploit, Third Party Advisory
References () https://www.h3c.com/cn/d_202308/1912371_30005_0.htm - () https://www.h3c.com/cn/d_202308/1912371_30005_0.htm - Product

20 Mar 2025, 14:15

Type Values Removed Values Added
CWE CWE-259

19 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

19 Aug 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) Se descubrió que H3C GR1100-P v100R009 utiliza una contraseña codificada en /etc/shadow, que permite a los atacantes iniciar sesión como superusuario.

16 Aug 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-16 18:15

Updated : 2025-05-27 17:52


NVD link : CVE-2024-42639

Mitre link : CVE-2024-42639

CVE.ORG link : CVE-2024-42639


JSON object : View

Products Affected

h3c

  • gr1100-p
  • gr1100-p_firmware
CWE
CWE-259

Use of Hard-coded Password