CVE-2013-6035
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.58% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- gatehouse/gatehouse · harris/bgan · hughes network systems/9201 · hughes network systems/9450 · hughes network systems/9502 · inmarsat/inmarsat · japan radio/jue-250 · japan radio/jue-500 · thuraya telecommunications/ip
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/250358US Government Resource
- http://www.kb.cert.org/vuls/id/250358US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.