Lucene search

K
cve[email protected]CVE-2014-0328
HistoryAug 15, 2014 - 11:15 a.m.

CVE-2014-0328

2014-08-1511:15:42
web.nvd.nist.gov
36
cve-2014-0328
cobham devices
thranelink protocol
firmware signatures
remote code execution
snmp
tftp
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%

The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary code by leveraging physical access or terminal access to send an SNMP request and a TFTP response.

Affected configurations

NVD
Node
cobhamailor_6110_mini-c_gmdssMatch-
OR
cobhamsailor_6006_message_terminalMatch-
OR
cobhamsailor_6222_vhfMatch-
OR
cobhamsailor_6300_mf_\/_hfMatch-

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

73.0%

Related for CVE-2014-0328