PT-2014-4972 · Cobham · Cobham Aviator

Ruben Santamarta

·

Published

2014-09-22

·

Updated

2014-09-22

·

CVE-2014-2942

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cobham Aviator versions 700D and 700E
Description The issue concerns an improper algorithm used for PIN codes in the affected satellite terminals, making it easier for attackers to calculate the superuser code. This could allow attackers to obtain a privileged terminal session by leveraging physical access or terminal access to enter the calculated code.
Recommendations For Cobham Aviator 700D, update the PIN code algorithm to prevent easy calculation of the superuser code. For Cobham Aviator 700E, update the PIN code algorithm to prevent easy calculation of the superuser code. As a temporary workaround, consider restricting physical and terminal access to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2942

Affected Products

Cobham Aviator