CVE-2018-19392 Information
Feb 14, 2021
cve
Description
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account’s password (including the default \admin\ account) without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange passwordAdmChange1 and passwordAdmChange2 fields).
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://cyberskr.com/blog/cobham-satcom-250-500.html https://gist.github.com/CyberSKR/2dfd5dccb20a209ec4d35b2678bac0d4
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: