SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-9531

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454.

CRITICAL 9.8EPSS 2.50%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (2.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to port 5454. This could allow an unauthenticated, remote attacker to connect to this port via Telnet and execute 86 Attention (AT) commands, including some that provide unauthenticated, shell-like access to the device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
2.50% probability · 84th percentile
CISA KEV
Not listed
Weakness
CWE-284, CWE-287
Affected
cobham/explorer 710 firmware
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.