CVE-2018-19393
Summary
| CVE | CVE-2018-19393 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-15 16:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this vulnerability could be leveraged to achieve a Denial of Service (DoS) condition, where the device would require a factory reset to return to normal operation. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Cobham | Satcom Sailor 800 | - | All | All | All |
| Hardware | Cobham | Satcom Sailor 800 | - | All | All | All |
| Operating System | Cobham | Satcom Sailor 800 Firmware | - | All | All | All |
| Operating System | Cobham | Satcom Sailor 800 Firmware | - | All | All | All |
| Hardware | Cobham | Satcom Sailor 900 | - | All | All | All |
| Hardware | Cobham | Satcom Sailor 900 | - | All | All | All |
| Operating System | Cobham | Satcom Sailor 900 Firmware | - | All | All | All |
| Operating System | Cobham | Satcom Sailor 900 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2018-19393: The Cobham Satcom Sailor 800 and Sailor 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. · GitHub | MISC | gist.github.com | Third Party Advisory |
| CyberSKR - Cyber Security Consultancy | MISC | cyberskr.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.