CVE-2013-7180
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows attackers to obtain administrative privileges by leveraging physical…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows attackers to obtain administrative privileges by leveraging physical access or terminal access to spoof a reset code.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 1.88% probability · 78th percentile
- CISA KEV
- Not listed
- Affected
- cobham/aviator 200 · cobham/aviator 300 · cobham/aviator 350 · cobham/aviator 700d · cobham/explorer bgan · cobham/sailor 900 vsat · cobham/sailor fleetbroadband 150 · cobham/sailor fleetbroadband 250 · cobham/sailor fleetbroadband 500
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/602006Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/602006Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.