CVE Vulnerabilities

CVE-2014-0328

Published: Aug 15, 2014 | Modified: Aug 15, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response.

Affected Software

Name Vendor Start Version End Version
Ailor_6110_mini-c_gmdss Cobham - (including) - (including)
Sailor_6006_message_terminal Cobham - (including) - (including)
Sailor_6222_vhf Cobham - (including) - (including)
Sailor_6300_mf_/_hf Cobham - (including) - (including)

References