Cobham Aviator 700D and 700E local information leakage Vulnerability (CVE-2014-2943)
Release date:
Updated on:
Affected Systems:
Cobham Aviator 700D
Description:
--------------------------------------------------------------------------------
Bugtraq id: 69138
CVE (CAN) ID: CVE-2014-2943
Cobham Aviator 700D and 700E are satellite communication terminal products.
Cobham Aviator 700D and 700E use a risky encryption algorithm to generate a PIN code to access the terminal. This algorithm is reversible. Local attackers can exploit this vulnerability to generate a superuser PIN code.
<* Source: Ruben Santamarta (ruben@reversemode.com)
Link: http://www.kb.cert.org/vuls/id/882207
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Cobham
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.cobham.com
This article permanently updates the link address: