// For flags

CVE-2014-2942

 

Severity Score

6.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculating the superuser code, and then leveraging physical access or terminal access to enter this code.

Los terminales de satélite Cobham Aviator 700D y 700E utiliza un algoritmo inadecuado para códigos PIN, lo que facilita a atacantes obtener sesiones de terminales privilegiadas calculando el código de superusuario, y luego aprovechar el acceso físico o acceso al terminal para introducir este código.

*Credits: N/A
CVSS Scores
Attack Vector
Physical
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-04-21 CVE Reserved
  • 2014-09-22 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-255: Credentials Management Errors
CAPEC
References (1)
URL Tag Source
http://www.kb.cert.org/vuls/id/882207 Third Party Advisory
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cobham
Search vendor "Cobham"
Aviator 700d
Search vendor "Cobham" for product "Aviator 700d"
--
Affected
Cobham
Search vendor "Cobham"
Aviator 700e
Search vendor "Cobham" for product "Aviator 700e"
--
Affected