PatchSiren cyber security CVE debrief
CVE-2024-42495 Hughes Network Systems CVE debrief
CVE-2024-42495 (CVSS 6.5, Medium) describes a cleartext credential transmission vulnerability in Hughes Network Systems WL3000 Fusion Software, published 2024-09-05. Device configuration credentials were transmitted via an unencrypted protocol, enabling read-only access to network and terminal configuration data for attackers with adjacent network access. The attack vector is adjacent (AV:A), requires no privileges or user interaction (PR:N/UI:N), and results in high confidentiality impact (C:H) with no integrity or availability impact. Hughes Network Systems has patched this vulnerability; no user action is required. Organizations should contact Hughes customer support with any questions.
- Vendor
- Hughes Network Systems
- Product
- WL3000 Fusion Software
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-05
- Original CVE updated
- 2024-09-05
- Advisory published
- 2024-09-05
- Advisory updated
- 2024-09-05
Who should care
Satellite network operators, critical infrastructure providers using Hughes satellite terminals, ICS/SCADA security teams, and organizations with remote site connectivity via Hughes WL3000 systems.
Technical summary
The WL3000 Fusion Software transmitted device configuration credentials without encryption. An attacker with adjacent network access could intercept these credentials, gaining read-only access to network configuration and terminal configuration data. The vulnerability does not permit modification of configuration or disruption of service. Hughes Network Systems has deployed patches automatically; affected systems should be running version 2.7.0.10 or later.
Defensive priority
medium
Recommended defensive actions
- Contact Hughes Network Systems customer support if questions remain about patch deployment status for WL3000 Fusion Software.
- Verify WL3000 Fusion Software is running version 2.7.0.10 or later.
- Segment satellite terminal management networks from untrusted or guest networks to limit adjacent attack vectors.
- Monitor network traffic for unencrypted credential exchanges on management interfaces.
- Apply CISA ICS recommended practices for defense-in-depth strategies in satellite/SCADA environments.
Evidence notes
CISA ICS Advisory ICSA-24-249-01 confirms Hughes Network Systems patched the vulnerability with no user action required. CVSS 3.1 vector AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N indicates adjacent network access is required.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-42495 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-42495
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-42495 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-42495
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-249-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-249-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.