Cobham kayıtları
cobham üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-284 Improper Access Control3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-319 Cleartext Transmission of Sensitive Information1
- CWE-494 Download of Code Without Integrity Check1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2014-2940İstismar yok | Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator accountcobham · sailor 900 firmware | Kritik10,0 | — | %2,2 | 15 Ağu 2014 |
40Planlayın | CVE-2018-5267İstismar yok | Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDealecobham · sea tel 121 firmware | Kritik9,8 | — | %2,5 | 7 Oca 2018 |
40Planlayın | CVE-2019-9531İstismar yok | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to a port that can run AT commandscobham · explorer 710 firmware · CWE-284 | Kritik9,8 | — | %2,5 | 10 Eki 2019 |
39İzleyin | CVE-2019-9533İstismar yok | The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08cobham · explorer 710 firmware · CWE-522 | Kritik9,8 | — | %1,5 | 10 Eki 2019 |
39İzleyin | CVE-2018-19392İstismar yok | Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability.cobham · satcom sailor 250 firmware · CWE-287 | Kritik9,8 | — | %1,4 | 15 Mar 2019 |
38İzleyin | CVE-2014-0328İstismar yok | The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary cocobham · ailor 6110 mini-c gmdss | Kritik9,3 | — | %2,8 | 15 Ağu 2014 |
32İzleyin | CVE-2013-7180İstismar yok | Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly cobham · aviator 200 | Yüksek7,8 | — | %1,9 | 15 Ağu 2014 |
32İzleyin | CVE-2023-44857İstismar yok | An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 functicobham · sailor 600 vsat ku firmware · CWE-94 | Yüksek8,1 | — | %0,9 | 12 Nis 2024 |
32İzleyin | CVE-2023-44852İstismar yok | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Yüksek8,2 | — | %0,6 | 12 Nis 2024 |
31İzleyin | CVE-2018-5266İstismar yok | Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading cobham · sea tel 121 firmware · CWE-200 | Yüksek7,5 | — | %2,0 | 7 Oca 2018 |
31İzleyin | CVE-2019-9534İstismar yok | The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware imagecobham · explorer 710 firmware · CWE-494 | Yüksek7,8 | — | %0,2 | 10 Eki 2019 |
31İzleyin | CVE-2019-9532İstismar yok | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartextcobham · explorer 710 firmware · CWE-319 | Yüksek7,8 | — | %0,2 | 10 Eki 2019 |
30İzleyin | CVE-2018-19393İstismar yok | Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuraticobham · satcom sailor 800 firmware · CWE-732 | Yüksek7,5 | — | %1,5 | 15 Mar 2019 |
29İzleyin | CVE-2014-2941İstismar yok | Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 commandcobham · ailor 6110 mini-c gmdss | Yüksek7,1 | — | %2,0 | 15 Ağu 2014 |
28İzleyin | CVE-2014-2942İstismar yok | Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a prcobham · aviator 700d · CWE-255 | Yüksek7,2 | — | %0,4 | 22 Eyl 2014 |
27İzleyin | CVE-2014-2964İstismar yok | Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, whicobham · aviator 700d | Orta6,9 | — | %0,5 | 15 Ağu 2014 |
26İzleyin | CVE-2023-44855İstismar yok | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a craftedcobham · sailor 600 vsat ku firmware · CWE-79 | Orta6,5 | — | %0,5 | 12 Nis 2024 |
24İzleyin | CVE-2018-19391İstismar yok | Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor vcobham · satcom sailor 250 firmware · CWE-79 | Orta6,1 | — | %0,7 | 15 Mar 2019 |
24İzleyin | CVE-2023-44854İstismar yok | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Orta6,1 | — | %0,5 | 12 Nis 2024 |
24İzleyin | CVE-2023-44856İstismar yok | Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a craftecobham · sailor 600 vsat ku firmware · CWE-79 | Orta6,1 | — | %0,5 | 12 Nis 2024 |
22İzleyin | CVE-2019-9530İstismar yok | The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all filescobham · explorer 710 firmware · CWE-284 | Orta5,5 | — | %0,4 | 10 Eki 2019 |
22İzleyin | CVE-2019-9529İstismar yok | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by defaultcobham · explorer 710 firmware · CWE-284 | Orta5,5 | — | %0,3 | 10 Eki 2019 |
21İzleyin | CVE-2018-5728İstismar yok | Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus requecobham · seatel 121 firmware · CWE-200 | Orta5,3 | — | %1,3 | 16 Oca 2018 |
21İzleyin | CVE-2019-16320İstismar yok | Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latitcobham · sea tel coastal 18 firmware · CWE-200 | Orta5,3 | — | %1,1 | 15 Eyl 2019 |
21İzleyin | CVE-2018-5071İstismar yok | Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can injecobham · sea tel 116 firmware · CWE-79 | Orta5,4 | — | %0,8 | 7 Oca 2018 |
- CVE-2014-294041Planlayın
Cobham Sailor 900 and 6000 satellite terminals with firmware 1.08 MFHF and 2.11 VHF have hardcoded credentials for the administrator account
KritikCVSS 10,0İstismar yokEPSS %2cobham · sailor 900 firmware15 Ağu 2014
- CVE-2018-526740Planlayın
Cobham Sea Tel 121 build 222701 devices allow remote attackers to bypass authentication via a direct request to MenuDealerGx.html, MenuDeale
KritikCVSS 9,8İstismar yokEPSS %3cobham · sea tel 121 firmware7 Oca 2018
- CVE-2019-953140Planlayın
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, allows unauthenticated access to a port that can run AT commands
KritikCVSS 9,8İstismar yokEPSS %3cobham · explorer 710 firmware10 Eki 2019
- CVE-2019-953339İzleyin
The root password of the Cobham EXPLORER 710 is the same for all versions of firmware up to and including v1.08
KritikCVSS 9,8İstismar yokEPSS %2cobham · explorer 710 firmware10 Eki 2019
- CVE-2018-1939239İzleyin
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1cobham · satcom sailor 250 firmware15 Mar 2019
- CVE-2014-032838İzleyin
The thraneLINK protocol implementation on Cobham devices does not verify firmware signatures, which allows attackers to execute arbitrary co
KritikCVSS 9,3İstismar yokEPSS %3cobham · ailor 6110 mini-c gmdss15 Ağu 2014
- CVE-2013-718032İzleyin
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly
YüksekCVSS 7,8İstismar yokEPSS %2cobham · aviator 20015 Ağu 2014
- CVE-2023-4485732İzleyin
An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 functi
YüksekCVSS 8,1İstismar yokEPSS %1cobham · sailor 600 vsat ku firmware12 Nis 2024
- CVE-2023-4485232İzleyin
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
YüksekCVSS 8,2İstismar yokEPSS %1cobham · sailor 600 vsat ku firmware12 Nis 2024
- CVE-2018-526631İzleyin
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading
YüksekCVSS 7,5İstismar yokEPSS %2cobham · sea tel 121 firmware7 Oca 2018
- CVE-2019-953431İzleyin
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image
YüksekCVSS 7,8İstismar yokEPSS %0cobham · explorer 710 firmware10 Eki 2019
- CVE-2019-953231İzleyin
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext
YüksekCVSS 7,8İstismar yokEPSS %0cobham · explorer 710 firmware10 Eki 2019
- CVE-2018-1939330İzleyin
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configurati
YüksekCVSS 7,5İstismar yokEPSS %2cobham · satcom sailor 800 firmware15 Mar 2019
- CVE-2014-294129İzleyin
Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command
YüksekCVSS 7,1İstismar yokEPSS %2cobham · ailor 6110 mini-c gmdss15 Ağu 2014
- CVE-2014-294228İzleyin
Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a pr
YüksekCVSS 7,2İstismar yokEPSS %0cobham · aviator 700d22 Eyl 2014
- CVE-2014-296427İzleyin
Cobham Aviator 700D and 700E satellite terminals have hardcoded passwords for the (1) debug, (2) prod, (3) do160, and (4) flrp programs, whi
OrtaCVSS 6,9İstismar yokEPSS %0cobham · aviator 700d15 Ağu 2014
- CVE-2023-4485526İzleyin
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted
OrtaCVSS 6,5İstismar yokEPSS %1cobham · sailor 600 vsat ku firmware12 Nis 2024
- CVE-2018-1939124İzleyin
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor v
OrtaCVSS 6,1İstismar yokEPSS %1cobham · satcom sailor 250 firmware15 Mar 2019
- CVE-2023-4485424İzleyin
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
OrtaCVSS 6,1İstismar yokEPSS %1cobham · sailor 600 vsat ku firmware12 Nis 2024
- CVE-2023-4485624İzleyin
Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafte
OrtaCVSS 6,1İstismar yokEPSS %1cobham · sailor 600 vsat ku firmware12 Nis 2024
- CVE-2019-953022İzleyin
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files
OrtaCVSS 5,5İstismar yokEPSS %0cobham · explorer 710 firmware10 Eki 2019
- CVE-2019-952922İzleyin
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default
OrtaCVSS 5,5İstismar yokEPSS %0cobham · explorer 710 firmware10 Eki 2019
- CVE-2018-572821İzleyin
Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information via a /cgi-bin/getSysStatus reque
OrtaCVSS 5,3İstismar yokEPSS %1cobham · seatel 121 firmware16 Oca 2018
- CVE-2019-1632021İzleyin
Cobham Sea Tel v170 224521 through v194 225444 devices allow attackers to obtain potentially sensitive information, such as a vessel's latit
OrtaCVSS 5,3İstismar yokEPSS %1cobham · sea tel coastal 18 firmware15 Eyl 2019
- CVE-2018-507121İzleyin
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inje
OrtaCVSS 5,4İstismar yokEPSS %1cobham · sea tel 116 firmware7 Oca 2018