The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development scripts left in the firmware can be used to upload a custom firmware image that the device runs. This could allow an unauthenticated, local attacker to upload their own firmware that could be used to intercept or modify traffic, spoof or intercept GPS traffic, exfiltrate private data, hide a backdoor, or cause a denial-of-service.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://kb.cert.org/vuls/id/719689/ |
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2019-10-10T20:09:47.814464Z
Updated: 2024-09-17T00:15:54.409Z
Reserved: 2019-03-01T00:00:00
Link: CVE-2019-9534
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-10-10T20:15:11.537
Modified: 2024-11-21T04:51:48.330
Link: CVE-2019-9534
Redhat
No data.