CVE Vulnerabilities

CVE-2013-6035

Improper Authentication

Published: Feb 04, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
GatehouseGatehouse- (including)- (including)
BganHarrisrf-7800b-du204 (including)rf-7800b-du204 (including)
BganHarrisrf-7800b-vu204 (including)rf-7800b-vu204 (including)
9201Hughes_network_systems- (including)- (including)
9450Hughes_network_systems- (including)- (including)
9502Hughes_network_systems- (including)- (including)
InmarsatInmarsat- (including)- (including)
Jue-250Japan_radio- (including)- (including)
Jue-500Japan_radio- (including)- (including)
IpThuraya_telecommunications- (including)- (including)

Potential Mitigations

References