CVE-2014-2940
Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account, which allows attackers to obtain administrative control by leveraging physical access or terminal access.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account, which allows attackers to obtain administrative control by leveraging physical access or terminal access.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- cobham/sailor 900 firmware · cobham/sailor 6000 series firmware
- Source
- cret@cert.org
References
- http://www.kb.cert.org/vuls/id/460687Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/460687Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.