Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19392

Опубликовано: 15 мар. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cobham:satcom_sailor_250_firmware:*:*:*:*:*:*:*:*
Версия до 1.25 (исключая)
cpe:2.3:h:cobham:satcom_sailor_250:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:cobham:satcom_sailor_500_firmware:*:*:*:*:*:*:*:*
Версия до 1.25 (исключая)
cpe:2.3:h:cobham:satcom_sailor_500:-:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.00967
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).

EPSS

Процентиль: 76%
0.00967
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-287