Arbiter Systems 1094B GPS Clock Insufficient Verification of Data Authenticity
Summary
| CVE | CVE-2014-9194 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-01-17 02:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Arbiter 1094B GPS Substation Clock allows remote attackers to cause a denial of service (disruption) via crafted radio transmissions that spoof GPS satellite broadcasts. |
Risk And Classification
Primary CVSS: v2.0 7.8 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:C
Problem Types: CWE-345 | CWE-19 | CWE-345 CWE-345
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 2.0 | [email protected] | Primary | 7.8 | AV:N/AC:L/Au:N/C:N/I:N/A:C | |
| 2.0 | [email protected] | Secondary | 5.4 | AV:N/AC:H/Au:N/C:N/I:N/A:C | |
| 2.0 | CNA | CVSS | 5.4 | AV:N/AC:H/Au:N/C:N/I:N/A:C |
CVSS v2.0 Breakdown
AV:N/AC:L/Au:N/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Arbiter | 1094b Gps Substation Clock | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Arbiter Systems | Model 1094B GPS Substation Clock | affected all versions | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/news-events/ics-advisories/icsa-14-345-01 | [email protected] | www.cisa.gov | |
| www.arbiter.com/contact/index.php | [email protected] | www.arbiter.com | |
| Arbiter Systems 1094B GPS Clock Spoofing Vulnerability | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Workarounds
CNA: Arbiter Systems would like to stress that they have not heard of this vulnerability being exploited in an actual control system. They have created a new product line, the 1200 series, which is not vulnerable to this type of attack. Arbiter Systems plans to continue to sell the 1094B model clock, because it is difficult to spoof the GPS signal and not likely to happen. In the unlikely event that the 1094B has been compromised, it can be recovered by removing and replacing the internal receiver battery. Arbiter Systems plans to investigate the feasibility of changing this model to protect against this type of exploit. Please contact Arbiter Systems Technical Support for additional questions: Phone: 1-800-321-3831 or 1-805-237-3831 Email: http://www.arbiter.com/contact/index.php