Overview
Broadband satellite terminals using Iridium Pilot and OpenPort have been found to contain undocumented hardcoded login credentials (CWE-798). Additionally, these broadband satellite terminals utilize an insecure proprietary communications protocol that allows unauthenticated users to perform privileged operations on the devices (CWE-306).
Description
Iridium Pilot and OpenPort are a shipboard communication device used to communicate voice and data from ship-to-ship and to ground stations through the Iridium satellite constellation. CWE-798 - Use of Hardcoded Credentials - CVE-2014-0326 |
Impact
A remote unauthenticated attacker may be able to gain privileged access to the device. Additionally, a remote unauthenticated attacker may be able to execute arbitrary code on the device. |
Solution
We are currently unaware of a practical solution to this problem. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 8.8 | E:F/RL:U/RC:C |
Environmental | 9.2 | CDP:LM/TD:H/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Cesar Cerrudo and Ruben Santamarta for reporting these vulnerabilities.
This document was written by Chris King.
Other Information
CVE IDs: | CVE-2014-0326, CVE-2014-0327 |
Date Public: | 2014-08-07 |
Date First Published: | 2014-08-07 |
Date Last Updated: | 2014-09-12 15:26 UTC |
Document Revision: | 40 |