PT-2014-3281 · Cobham · Cobham Sailor 900 Vsat+3

Ruben Santamarta

·

Published

2014-08-15

·

Updated

2014-08-15

·

CVE-2013-7180

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cobham SAILOR 900 VSAT SAILOR FleetBroadBand versions 150, 250, and 500 EXPLORER BGAN AVIATOR versions 200, 300, 350, and 700D
Description The issue allows attackers to obtain administrative privileges by leveraging physical access or terminal access to spoof a reset code, due to improper restriction of password recovery.
Recommendations For Cobham SAILOR 900 VSAT, restrict physical and terminal access to prevent spoofing of the reset code. For SAILOR FleetBroadband versions 150, 250, and 500, limit access to the device to minimize the risk of exploitation. For EXPLORER BGAN, consider implementing additional security measures to prevent unauthorized access. For AVIATOR versions 200, 300, 350, and 700D, restrict access to the device and its components to prevent administrative privilege escalation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-7180

Affected Products

Aviator
Cobham Sailor 900 Vsat
Explorer Bgan
Sailor Fleetbroadband