VulnerabilityModified
CVE-2014-0327
The Terminal Upgrade Tool in the Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allows remote attackers to execute arbitrary code by uploading new firmware to TCP port 54321.
HIGH 9.3EPSS 3.65%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Terminal Upgrade Tool in the Pilot Below Deck Equipment (BDE) and OpenPort implementations on Iridium satellite terminals allows remote attackers to execute arbitrary code by uploading new firmware to TCP port 54321.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.65% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- iridium/open port · iridium/pilot below deck equipment
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/578598Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/578598Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.