VulnerabilityModified
CVE-2019-9529
This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.
MEDIUM 5.5EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.28% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-306
- Affected
- cobham/explorer 710 firmware
- Source
- cret@cert.org
References
- https://kb.cert.org/vuls/id/719689/Third Party Advisory, US Government Resource
- https://kb.cert.org/vuls/id/719689/Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.