Vulnerability Description
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cobham | Ailor 6110 Mini-C Gmdss | - |
| Cobham | Sailor 6006 Message Terminal | - |
| Cobham | Sailor 6222 Vhf | - |
| Cobham | Sailor 6300 Mf \/ Hf | - |
References
- http://www.kb.cert.org/vuls/id/179732Third Party AdvisoryUS Government Resource
- http://www.kb.cert.org/vuls/id/179732Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2014-0328?
CVE-2014-0328 is a vulnerability with a CVSS score of 9.3 (HIGH). The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send ...
How severe is CVE-2014-0328?
CVE-2014-0328 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0328?
Check the references section above for vendor advisories and patch information. Affected products include: Cobham Ailor 6110 Mini-C Gmdss, Cobham Sailor 6006 Message Terminal, Cobham Sailor 6222 Vhf, Cobham Sailor 6300 Mf \/ Hf.