CVE Vulnerabilities

CVE-2013-6035

Improper Authentication

Published: Feb 04, 2014 | Modified: Feb 04, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Gatehouse Gatehouse - (including) - (including)
Bgan Harris rf-7800b-du204 (including) rf-7800b-du204 (including)
Bgan Harris rf-7800b-vu204 (including) rf-7800b-vu204 (including)
9201 Hughes_network_systems - (including) - (including)
9450 Hughes_network_systems - (including) - (including)
9502 Hughes_network_systems - (including) - (including)
Inmarsat Inmarsat - (including) - (including)
Jue-250 Japan_radio - (including) - (including)
Jue-500 Japan_radio - (including) - (including)
Ip Thuraya_telecommunications - (including) - (including)

Potential Mitigations

References