Vulnerability Description
The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a crafted 406 MHz digital signal.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cospas-Sarsat | Cospas-Sarsat System | - |
Related Weaknesses (CWE)
References
- https://conference.hitb.org/hitbsecconf2019ams/materials/D1T1%20-%20The%20BirdmaThird Party Advisory
- https://conference.hitb.org/hitbsecconf2019ams/sessions/the-birdman-hacking-cospThird Party Advisory
- https://conference.hitb.org/hitbsecconf2019ams/materials/D1T1%20-%20The%20BirdmaThird Party Advisory
- https://conference.hitb.org/hitbsecconf2019ams/sessions/the-birdman-hacking-cospThird Party Advisory
FAQ
What is CVE-2018-14062?
CVE-2018-14062 is a vulnerability with a CVSS score of 9.1 (CRITICAL). The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private messages (unrelated to distress alerts) via a craft...
How severe is CVE-2018-14062?
CVE-2018-14062 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-14062?
Check the references section above for vendor advisories and patch information. Affected products include: Cospas-Sarsat Cospas-Sarsat System.