Cobham records
27 published records for vendor cobham.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-284 Improper Access Control3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-494 Download of Code Without Integrity Check1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2014-2940No exploit | Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator accountcobham · sailor 900 firmware | Critical10.0 | — | 2.2% | Aug 15, 2014 |
40Plan | CVE-2018-5267No exploit | Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealecobham · sea tel 121 firmware | Critical9.8 | — | 2.5% | Jan 7, 2018 |
40Plan | CVE-2019-9531No exploit | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to a port that can run AT commandscobham · explorer 710 firmware · CWE-284 | Critical9.8 | — | 2.5% | Oct 10, 2019 |
39Monitor | CVE-2019-9533No exploit | The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08cobham · explorer 710 firmware · CWE-522 | Critical9.8 | — | 1.5% | Oct 10, 2019 |
39Monitor | CVE-2018-19392No exploit | Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability.cobham · satcom sailor 250 firmware · CWE-287 | Critical9.8 | — | 1.4% | Mar 15, 2019 |
38Monitor | CVE-2014-0328No exploit | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary cocobham · ailor 6110 mini-c gmdss | Critical9.3 | — | 2.8% | Aug 15, 2014 |
32Monitor | CVE-2013-7180No exploit | Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly cobham · aviator 200 | High7.8 | — | 1.9% | Aug 15, 2014 |
32Monitor | CVE-2023-44857No exploit | An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 functicobham · sailor 600 vsat ku firmware · CWE-94 | High8.1 | — | 0.9% | Apr 12, 2024 |
32Monitor | CVE-2023-44852No exploit | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | High8.2 | — | 0.6% | Apr 12, 2024 |
31Monitor | CVE-2018-5266No exploit | Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading cobham · sea tel 121 firmware · CWE-200 | High7.5 | — | 2.0% | Jan 7, 2018 |
31Monitor | CVE-2019-9534No exploit | The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware imagecobham · explorer 710 firmware · CWE-494 | High7.8 | — | 0.2% | Oct 10, 2019 |
31Monitor | CVE-2019-9532No exploit | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartextcobham · explorer 710 firmware · CWE-319 | High7.8 | — | 0.2% | Oct 10, 2019 |
30Monitor | CVE-2018-19393No exploit | Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuraticobham · satcom sailor 800 firmware · CWE-732 | High7.5 | — | 1.5% | Mar 15, 2019 |
29Monitor | CVE-2014-2941No exploit | Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 commandcobham · ailor 6110 mini-c gmdss | High7.1 | — | 2.0% | Aug 15, 2014 |
28Monitor | CVE-2014-2942No exploit | Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a prcobham · aviator 700d · CWE-255 | High7.2 | — | 0.4% | Sep 22, 2014 |
27Monitor | CVE-2014-2964No exploit | Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, whicobham · aviator 700d | Medium6.9 | — | 0.5% | Aug 15, 2014 |
26Monitor | CVE-2023-44855No exploit | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a craftedcobham · sailor 600 vsat ku firmware · CWE-79 | Medium6.5 | — | 0.5% | Apr 12, 2024 |
24Monitor | CVE-2018-19391No exploit | Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor vcobham · satcom sailor 250 firmware · CWE-79 | Medium6.1 | — | 0.7% | Mar 15, 2019 |
24Monitor | CVE-2023-44854No exploit | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Medium6.1 | — | 0.5% | Apr 12, 2024 |
24Monitor | CVE-2023-44856No exploit | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Medium6.1 | — | 0.5% | Apr 12, 2024 |
22Monitor | CVE-2019-9530No exploit | The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all filescobham · explorer 710 firmware · CWE-284 | Medium5.5 | — | 0.4% | Oct 10, 2019 |
22Monitor | CVE-2019-9529No exploit | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by defaultcobham · explorer 710 firmware · CWE-284 | Medium5.5 | — | 0.3% | Oct 10, 2019 |
21Monitor | CVE-2018-5728No exploit | Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus requecobham · seatel 121 firmware · CWE-200 | Medium5.3 | — | 1.3% | Jan 16, 2018 |
21Monitor | CVE-2019-16320No exploit | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitcobham · sea tel coastal 18 firmware · CWE-200 | Medium5.3 | — | 1.1% | Sep 15, 2019 |
21Monitor | CVE-2018-5071No exploit | Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can injecobham · sea tel 116 firmware · CWE-79 | Medium5.4 | — | 0.8% | Jan 7, 2018 |
- CVE-2014-294041Plan
Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account
CriticalCVSS 10.0No exploitEPSS 2%cobham · sailor 900 firmwareAug 15, 2014
- CVE-2018-526740Plan
Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDeale
CriticalCVSS 9.8No exploitEPSS 3%cobham · sea tel 121 firmwareJan 7, 2018
- CVE-2019-953140Plan
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to a port that can run AT commands
CriticalCVSS 9.8No exploitEPSS 3%cobham · explorer 710 firmwareOct 10, 2019
- CVE-2019-953339Monitor
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08
CriticalCVSS 9.8No exploitEPSS 2%cobham · explorer 710 firmwareOct 10, 2019
- CVE-2018-1939239Monitor
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%cobham · satcom sailor 250 firmwareMar 15, 2019
- CVE-2014-032838Monitor
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary co
CriticalCVSS 9.3No exploitEPSS 3%cobham · ailor 6110 mini-c gmdssAug 15, 2014
- CVE-2013-718032Monitor
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly
HighCVSS 7.8No exploitEPSS 2%cobham · aviator 200Aug 15, 2014
- CVE-2023-4485732Monitor
An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 functi
HighCVSS 8.1No exploitEPSS 1%cobham · sailor 600 vsat ku firmwareApr 12, 2024
- CVE-2023-4485232Monitor
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
HighCVSS 8.2No exploitEPSS 1%cobham · sailor 600 vsat ku firmwareApr 12, 2024
- CVE-2018-526631Monitor
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading
HighCVSS 7.5No exploitEPSS 2%cobham · sea tel 121 firmwareJan 7, 2018
- CVE-2019-953431Monitor
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image
HighCVSS 7.8No exploitEPSS 0%cobham · explorer 710 firmwareOct 10, 2019
- CVE-2019-953231Monitor
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext
HighCVSS 7.8No exploitEPSS 0%cobham · explorer 710 firmwareOct 10, 2019
- CVE-2018-1939330Monitor
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configurati
HighCVSS 7.5No exploitEPSS 2%cobham · satcom sailor 800 firmwareMar 15, 2019
- CVE-2014-294129Monitor
Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command
HighCVSS 7.1No exploitEPSS 2%cobham · ailor 6110 mini-c gmdssAug 15, 2014
- CVE-2014-294228Monitor
Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a pr
HighCVSS 7.2No exploitEPSS 0%cobham · aviator 700dSep 22, 2014
- CVE-2014-296427Monitor
Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, whi
MediumCVSS 6.9No exploitEPSS 0%cobham · aviator 700dAug 15, 2014
- CVE-2023-4485526Monitor
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted
MediumCVSS 6.5No exploitEPSS 1%cobham · sailor 600 vsat ku firmwareApr 12, 2024
- CVE-2018-1939124Monitor
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor v
MediumCVSS 6.1No exploitEPSS 1%cobham · satcom sailor 250 firmwareMar 15, 2019
- CVE-2023-4485424Monitor
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
MediumCVSS 6.1No exploitEPSS 1%cobham · sailor 600 vsat ku firmwareApr 12, 2024
- CVE-2023-4485624Monitor
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
MediumCVSS 6.1No exploitEPSS 1%cobham · sailor 600 vsat ku firmwareApr 12, 2024
- CVE-2019-953022Monitor
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files
MediumCVSS 5.5No exploitEPSS 0%cobham · explorer 710 firmwareOct 10, 2019
- CVE-2019-952922Monitor
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default
MediumCVSS 5.5No exploitEPSS 0%cobham · explorer 710 firmwareOct 10, 2019
- CVE-2018-572821Monitor
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus reque
MediumCVSS 5.3No exploitEPSS 1%cobham · seatel 121 firmwareJan 16, 2018
- CVE-2019-1632021Monitor
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latit
MediumCVSS 5.3No exploitEPSS 1%cobham · sea tel coastal 18 firmwareSep 15, 2019
- CVE-2018-507121Monitor
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inje
MediumCVSS 5.4No exploitEPSS 1%cobham · sea tel 116 firmwareJan 7, 2018