Overview
Some Cobham products have a web interface that contains a weak password recovery mechanism for the administrator account.
Description
CWE-640: Weak Password Recovery Mechanism for Forgotten Password IOActive has reported that Cobham SAILOR 900 VSAT, SAILOR FleetBroadBand 150/250/500, EXPLORER BGAN, and AVIATOR 200/300/350/700D have been identified with a weak password recovery mechanism. It is possible more products than what have been identified are affected. The password reset algorithm used by these products can be reverse engineered so an attacker may be able to generate their own reset codes to change the password of the administrator account. |
Impact
A remote unauthenticated attacker with access to the web interface may be able to reset the administrator password and take over the account. |
Solution
We are currently unaware of a practical solution to this problem. Please consider the following workaround. |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 7.8 | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Temporal | 6.3 | E:F/RL:W/RC:UC |
Environmental | 4.7 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/land-mobile-satcom-systems/products-and-services.aspx
- http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/satellite-communication-at-sea/products-and-services/inmarsat-fleetbroadband.aspx
- http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/land-mobile-satcom-systems/products-and-services/on-the-move-bgan.aspx
- http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/land-mobile-satcom-systems/products-and-services/ultra-portable-bgan.aspx
- http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/cockpit-and-cabin-communication/products-and-services/swiftbroadband-systems.aspx
- http://cwe.mitre.org/data/definitions/640.html
Acknowledgements
Thanks to Ruben Santamarta for reporting this vulnerability.
This document was written by Chris King.
Other Information
CVE IDs: | CVE-2013-7180 |
Date Public: | 2014-08-07 |
Date First Published: | 2014-08-07 |
Date Last Updated: | 2014-08-07 22:30 UTC |
Document Revision: | 27 |