Overview

Affected version

V100R009

Vulnerability description

H3C GR1100-PV100R009 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

Untitled

Additional Information

###Product_version
H3C GR1100-P
V100R009

###Affected_component
/etc/shadow

###Attack_vector
The root password obtained from /etc/shadow can be used for unauthorized root login.

###Discription
H3C GR1100-PV100R009 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

###Refernce
<https://palm-vertebra-fe9.notion.site/H3C-GR1100-PV100R009-was-discovered-to-contain-a-hardcoded-824141daa44f4c52a914860c6e4a7684>
<https://www.h3c.com/cn/d_202308/1912371_30005_0.htm>

Untitled

after decrypt the passwd we got root