CVE-2018-19392
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).
Los dispositivos Cobham Satcom Sailor 250 y 500, en versiones anteriores a la 1.25, contenían una vulnerabilidad de restablecimiento de contraseña no autenticada. Esto podría permitir la modificación de la contraseña de cualquier cuenta de usuario (incluyendo la cuenta "admin" por defecto) sin conocer su contraseña previamente. Todo lo que se requiere es conocer el nombre de usuario y el vector de ataque (los campos usernameAdmChange, passwordAdmChange1 y passwordAdmChange2 en /index.lua?pageID=Administration).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-20 CVE Reserved
- 2019-03-15 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gist.github.com/CyberSKR/2dfd5dccb20a209ec4d35b2678bac0d4 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://cyberskr.com/blog/cobham-satcom-250-500.html | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cobham Search vendor "Cobham" | Satcom Sailor 250 Firmware Search vendor "Cobham" for product "Satcom Sailor 250 Firmware" | < 1.25 Search vendor "Cobham" for product "Satcom Sailor 250 Firmware" and version " < 1.25" | - |
Affected
| in | Cobham Search vendor "Cobham" | Satcom Sailor 250 Search vendor "Cobham" for product "Satcom Sailor 250" | - | - |
Safe
|
Cobham Search vendor "Cobham" | Satcom Sailor 500 Firmware Search vendor "Cobham" for product "Satcom Sailor 500 Firmware" | < 1.25 Search vendor "Cobham" for product "Satcom Sailor 500 Firmware" and version " < 1.25" | - |
Affected
| in | Cobham Search vendor "Cobham" | Satcom Sailor 500 Search vendor "Cobham" for product "Satcom Sailor 500" | - | - |
Safe
|