PT-2014-4972 · Cobham · Cobham Aviator

Ruben Santamarta

·

Publicado

2014-09-22

·

Atualizado

2014-09-22

·

CVE-2014-2942

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cobham Aviator versions 700D and 700E
Description The issue concerns an improper algorithm used for PIN codes in the affected satellite terminals, making it easier for attackers to calculate the superuser code. This could allow attackers to obtain a privileged terminal session by leveraging physical access or terminal access to enter the calculated code.
Recommendations For Cobham Aviator 700D, update the PIN code algorithm to prevent easy calculation of the superuser code. For Cobham Aviator 700E, update the PIN code algorithm to prevent easy calculation of the superuser code. As a temporary workaround, consider restricting physical and terminal access to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2942

Produtos afetados

Cobham Aviator