PT-2014-4972 · Cobham · Cobham Aviator
Ruben Santamarta
·
Published
2014-09-22
·
Updated
2014-09-22
·
CVE-2014-2942
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Cobham Aviator versions 700D and 700E
Description
The issue concerns an improper algorithm used for PIN codes in the affected satellite terminals, making it easier for attackers to calculate the superuser code. This could allow attackers to obtain a privileged terminal session by leveraging physical access or terminal access to enter the calculated code.
Recommendations
For Cobham Aviator 700D, update the PIN code algorithm to prevent easy calculation of the superuser code.
For Cobham Aviator 700E, update the PIN code algorithm to prevent easy calculation of the superuser code.
As a temporary workaround, consider restricting physical and terminal access to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cobham Aviator