Lucene search

K
cve[email protected]CVE-2019-9529
HistoryOct 10, 2019 - 8:15 p.m.

CVE-2019-9529

2019-10-1020:15:11
CWE-306
CWE-284
web.nvd.nist.gov
87
cobham
explorer 710
firmware
authentication
vulnerability
web application
nvd
cve-2019-9529

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:C/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.

Affected configurations

NVD
Node
cobhamexplorer_710_firmwareMatch1.07
AND
cobhamexplorer_710Match-

CNA Affected

[
  {
    "product": "Explorer 710",
    "vendor": "Cobham plc",
    "versions": [
      {
        "status": "affected",
        "version": "1.07"
      }
    ]
  }
]

4.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

COMPLETE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:C/A:N

5.5 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

6.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

0.4%

Related for CVE-2019-9529