Записи Cobham
27 опубликованных записей вендора cobham.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-284 Improper Access Control3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-494 Download of Code Without Integrity Check1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2014-2940Эксплойта нет | Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator accountcobham · sailor 900 firmware | Критическая10,0 | — | 2,2 % | 15 авг. 2014 г. |
40В плане | CVE-2018-5267Эксплойта нет | Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealecobham · sea tel 121 firmware | Критическая9,8 | — | 2,5 % | 7 янв. 2018 г. |
40В плане | CVE-2019-9531Эксплойта нет | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to a port that can run AT commandscobham · explorer 710 firmware · CWE-284 | Критическая9,8 | — | 2,5 % | 10 окт. 2019 г. |
39Наблюдать | CVE-2019-9533Эксплойта нет | The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08cobham · explorer 710 firmware · CWE-522 | Критическая9,8 | — | 1,5 % | 10 окт. 2019 г. |
39Наблюдать | CVE-2018-19392Эксплойта нет | Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability.cobham · satcom sailor 250 firmware · CWE-287 | Критическая9,8 | — | 1,4 % | 15 мар. 2019 г. |
38Наблюдать | CVE-2014-0328Эксплойта нет | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary cocobham · ailor 6110 mini-c gmdss | Критическая9,3 | — | 2,8 % | 15 авг. 2014 г. |
32Наблюдать | CVE-2013-7180Эксплойта нет | Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly cobham · aviator 200 | Высокая7,8 | — | 1,9 % | 15 авг. 2014 г. |
32Наблюдать | CVE-2023-44857Эксплойта нет | An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 functicobham · sailor 600 vsat ku firmware · CWE-94 | Высокая8,1 | — | 0,9 % | 12 апр. 2024 г. |
32Наблюдать | CVE-2023-44852Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Высокая8,2 | — | 0,6 % | 12 апр. 2024 г. |
31Наблюдать | CVE-2018-5266Эксплойта нет | Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading cobham · sea tel 121 firmware · CWE-200 | Высокая7,5 | — | 2,0 % | 7 янв. 2018 г. |
31Наблюдать | CVE-2019-9534Эксплойта нет | The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware imagecobham · explorer 710 firmware · CWE-494 | Высокая7,8 | — | 0,2 % | 10 окт. 2019 г. |
31Наблюдать | CVE-2019-9532Эксплойта нет | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartextcobham · explorer 710 firmware · CWE-319 | Высокая7,8 | — | 0,2 % | 10 окт. 2019 г. |
30Наблюдать | CVE-2018-19393Эксплойта нет | Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuraticobham · satcom sailor 800 firmware · CWE-732 | Высокая7,5 | — | 1,5 % | 15 мар. 2019 г. |
29Наблюдать | CVE-2014-2941Эксплойта нет | Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 commandcobham · ailor 6110 mini-c gmdss | Высокая7,1 | — | 2,0 % | 15 авг. 2014 г. |
28Наблюдать | CVE-2014-2942Эксплойта нет | Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a prcobham · aviator 700d · CWE-255 | Высокая7,2 | — | 0,4 % | 22 сент. 2014 г. |
27Наблюдать | CVE-2014-2964Эксплойта нет | Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, whicobham · aviator 700d | Средняя6,9 | — | 0,5 % | 15 авг. 2014 г. |
26Наблюдать | CVE-2023-44855Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a craftedcobham · sailor 600 vsat ku firmware · CWE-79 | Средняя6,5 | — | 0,5 % | 12 апр. 2024 г. |
24Наблюдать | CVE-2018-19391Эксплойта нет | Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor vcobham · satcom sailor 250 firmware · CWE-79 | Средняя6,1 | — | 0,7 % | 15 мар. 2019 г. |
24Наблюдать | CVE-2023-44854Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Средняя6,1 | — | 0,5 % | 12 апр. 2024 г. |
24Наблюдать | CVE-2023-44856Эксплойта нет | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Средняя6,1 | — | 0,5 % | 12 апр. 2024 г. |
22Наблюдать | CVE-2019-9530Эксплойта нет | The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all filescobham · explorer 710 firmware · CWE-284 | Средняя5,5 | — | 0,4 % | 10 окт. 2019 г. |
22Наблюдать | CVE-2019-9529Эксплойта нет | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by defaultcobham · explorer 710 firmware · CWE-284 | Средняя5,5 | — | 0,3 % | 10 окт. 2019 г. |
21Наблюдать | CVE-2018-5728Эксплойта нет | Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus requecobham · seatel 121 firmware · CWE-200 | Средняя5,3 | — | 1,3 % | 16 янв. 2018 г. |
21Наблюдать | CVE-2019-16320Эксплойта нет | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitcobham · sea tel coastal 18 firmware · CWE-200 | Средняя5,3 | — | 1,1 % | 15 сент. 2019 г. |
21Наблюдать | CVE-2018-5071Эксплойта нет | Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can injecobham · sea tel 116 firmware · CWE-79 | Средняя5,4 | — | 0,8 % | 7 янв. 2018 г. |
- CVE-2014-294041В плане
Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %cobham · sailor 900 firmware15 авг. 2014 г.
- CVE-2018-526740В плане
Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDeale
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cobham · sea tel 121 firmware7 янв. 2018 г.
- CVE-2019-953140В плане
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to a port that can run AT commands
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cobham · explorer 710 firmware10 окт. 2019 г.
- CVE-2019-953339Наблюдать
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cobham · explorer 710 firmware10 окт. 2019 г.
- CVE-2018-1939239Наблюдать
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cobham · satcom sailor 250 firmware15 мар. 2019 г.
- CVE-2014-032838Наблюдать
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary co
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %cobham · ailor 6110 mini-c gmdss15 авг. 2014 г.
- CVE-2013-718032Наблюдать
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %cobham · aviator 20015 авг. 2014 г.
- CVE-2023-4485732Наблюдать
An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 functi
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %cobham · sailor 600 vsat ku firmware12 апр. 2024 г.
- CVE-2023-4485232Наблюдать
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %cobham · sailor 600 vsat ku firmware12 апр. 2024 г.
- CVE-2018-526631Наблюдать
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cobham · sea tel 121 firmware7 янв. 2018 г.
- CVE-2019-953431Наблюдать
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %cobham · explorer 710 firmware10 окт. 2019 г.
- CVE-2019-953231Наблюдать
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %cobham · explorer 710 firmware10 окт. 2019 г.
- CVE-2018-1939330Наблюдать
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configurati
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cobham · satcom sailor 800 firmware15 мар. 2019 г.
- CVE-2014-294129Наблюдать
Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command
ВысокаяCVSS 7,1Эксплойта нетEPSS 2 %cobham · ailor 6110 mini-c gmdss15 авг. 2014 г.
- CVE-2014-294228Наблюдать
Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a pr
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %cobham · aviator 700d22 сент. 2014 г.
- CVE-2014-296427Наблюдать
Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, whi
СредняяCVSS 6,9Эксплойта нетEPSS 0 %cobham · aviator 700d15 авг. 2014 г.
- CVE-2023-4485526Наблюдать
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cobham · sailor 600 vsat ku firmware12 апр. 2024 г.
- CVE-2018-1939124Наблюдать
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor v
СредняяCVSS 6,1Эксплойта нетEPSS 1 %cobham · satcom sailor 250 firmware15 мар. 2019 г.
- CVE-2023-4485424Наблюдать
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
СредняяCVSS 6,1Эксплойта нетEPSS 1 %cobham · sailor 600 vsat ku firmware12 апр. 2024 г.
- CVE-2023-4485624Наблюдать
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
СредняяCVSS 6,1Эксплойта нетEPSS 1 %cobham · sailor 600 vsat ku firmware12 апр. 2024 г.
- CVE-2019-953022Наблюдать
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files
СредняяCVSS 5,5Эксплойта нетEPSS 0 %cobham · explorer 710 firmware10 окт. 2019 г.
- CVE-2019-952922Наблюдать
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default
СредняяCVSS 5,5Эксплойта нетEPSS 0 %cobham · explorer 710 firmware10 окт. 2019 г.
- CVE-2018-572821Наблюдать
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus reque
СредняяCVSS 5,3Эксплойта нетEPSS 1 %cobham · seatel 121 firmware16 янв. 2018 г.
- CVE-2019-1632021Наблюдать
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latit
СредняяCVSS 5,3Эксплойта нетEPSS 1 %cobham · sea tel coastal 18 firmware15 сент. 2019 г.
- CVE-2018-507121Наблюдать
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inje
СредняяCVSS 5,4Эксплойта нетEPSS 1 %cobham · sea tel 116 firmware7 янв. 2018 г.