ID

VAR-201408-0270


CVE

CVE-2014-2941


TITLE

Cobham Sailor 6000 series satellite terminal contain hardcoded credentials

Trust: 0.8

sources: CERT/CC: VU#269991

DESCRIPTION

Cobham Sailor 6000 satellite terminals have hardcoded Tbus 2 credentials, which allows remote attackers to obtain access via a TBUS2 command. NOTE: the vendor reportedly states "there is no possibility to exploit another user's credentials. ** Unsettled ** This case has not been confirmed as a vulnerability. Tbus 2 Protocol is the protocol used for device maintenance. The vulnerability is VU#460687 It is a different problem. CWE-798: Use of Hard-coded Credentials https://cwe.mitre.org/data/definitions/798.html In addition, the vendor says that “There is no possibility of misusing other users' certificates”.Any by a third party Tbus 2 Commands may be sent and the system may be operated. The Cobham Sailor 6000 Series has a security bypass vulnerability. An attacker could exploit the vulnerability to bypass the authentication mechanism and gain access to the affected device

Trust: 3.15

sources: NVD: CVE-2014-2941 // CERT/CC: VU#269991 // JVNDB: JVNDB-2014-003714 // CNVD: CNVD-2014-04963 // BID: 69139

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-04963

AFFECTED PRODUCTS

vendor:cobhammodel:sailor 6300 mf \/ hfscope:eqversion: -

Trust: 1.6

vendor:cobhammodel:sailor 6006 message terminalscope:eqversion: -

Trust: 1.6

vendor:cobhammodel:ailor 6110 mini-c gmdssscope:eqversion: -

Trust: 1.6

vendor:cobhammodel:sailor 6222 vhfscope:eqversion: -

Trust: 1.6

vendor:cobham plcmodel: - scope: - version: -

Trust: 0.8

vendor:cobham plcmodel:sailor 6006 message terminalscope: - version: -

Trust: 0.8

vendor:cobham plcmodel:sailor 6110 mini-c gmdssscope: - version: -

Trust: 0.8

vendor:cobham plcmodel:sailor 6222 vhfscope: - version: -

Trust: 0.8

vendor:cobham plcmodel:sailor 6300 mf/hfscope: - version: -

Trust: 0.8

vendor:cobhammodel:sailor seriesscope:eqversion:6000

Trust: 0.6

vendor:cobhammodel:plc sailor seriesscope:eqversion:60000

Trust: 0.3

sources: CERT/CC: VU#269991 // CNVD: CNVD-2014-04963 // BID: 69139 // JVNDB: JVNDB-2014-003714 // CNNVD: CNNVD-201408-149 // NVD: CVE-2014-2941

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2014-2941
value: HIGH

Trust: 1.6

nvd@nist.gov: CVE-2014-2941
value: HIGH

Trust: 1.0

CNVD: CNVD-2014-04963
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201408-149
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2014-2941
severity: HIGH
baseScore: 7.1
vectorString: AV:N/AC:M/AU:N/C:N/I:C/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2014-2941
severity: HIGH
baseScore: 7.1
vectorString: NONE
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

CNVD: CNVD-2014-04963
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CERT/CC: VU#269991 // CNVD: CNVD-2014-04963 // JVNDB: JVNDB-2014-003714 // CNNVD: CNNVD-201408-149 // NVD: CVE-2014-2941

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2014-003714 // NVD: CVE-2014-2941

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201408-149

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-201408-149

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003714

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#269991

PATCH

title:Aerospace and Security, SATCOM, Inmarsat FleetBroadband:url:http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/satellite-communication-at-sea/products-and-services/inmarsat-fleetbroadband.aspx

Trust: 0.8

sources: JVNDB: JVNDB-2014-003714

EXTERNAL IDS

db:CERT/CCid:VU#269991

Trust: 3.5

db:NVDid:CVE-2014-2941

Trust: 3.3

db:BIDid:69139

Trust: 1.5

db:JVNid:JVNVU91780498

Trust: 0.8

db:JVNDBid:JVNDB-2014-003714

Trust: 0.8

db:CNVDid:CNVD-2014-04963

Trust: 0.6

db:CNNVDid:CNNVD-201408-149

Trust: 0.6

sources: CERT/CC: VU#269991 // CNVD: CNVD-2014-04963 // BID: 69139 // JVNDB: JVNDB-2014-003714 // CNNVD: CNNVD-201408-149 // NVD: CVE-2014-2941

REFERENCES

url:http://www.kb.cert.org/vuls/id/269991

Trust: 2.7

url:http://www.securityfocus.com/bid/69139

Trust: 1.2

url:http://www.cobham.com/about-cobham/aerospace-and-security/about-us/satcom/satellite-communication-at-sea/products-and-services/inmarsat-fleetbroadband.aspx

Trust: 1.1

url:http://cwe.mitre.org/data/definitions/798.html

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2941

Trust: 0.8

url:http://jvn.jp/vu/jvnvu91780498/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2941

Trust: 0.8

sources: CERT/CC: VU#269991 // CNVD: CNVD-2014-04963 // BID: 69139 // JVNDB: JVNDB-2014-003714 // CNNVD: CNNVD-201408-149 // NVD: CVE-2014-2941

CREDITS

Ruben Santamarta

Trust: 0.9

sources: BID: 69139 // CNNVD: CNNVD-201408-149

SOURCES

db:CERT/CCid:VU#269991
db:CNVDid:CNVD-2014-04963
db:BIDid:69139
db:JVNDBid:JVNDB-2014-003714
db:CNNVDid:CNNVD-201408-149
db:NVDid:CVE-2014-2941

LAST UPDATE DATE

2025-04-13T21:36:31.624000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#269991date:2014-08-14T00:00:00
db:CNVDid:CNVD-2014-04963date:2014-08-13T00:00:00
db:BIDid:69139date:2014-08-07T00:00:00
db:JVNDBid:JVNDB-2014-003714date:2015-11-11T00:00:00
db:CNNVDid:CNNVD-201408-149date:2014-08-18T00:00:00
db:NVDid:CVE-2014-2941date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#269991date:2014-08-07T00:00:00
db:CNVDid:CNVD-2014-04963date:2014-08-13T00:00:00
db:BIDid:69139date:2014-08-07T00:00:00
db:JVNDBid:JVNDB-2014-003714date:2014-08-11T00:00:00
db:CNNVDid:CNNVD-201408-149date:2014-08-12T00:00:00
db:NVDid:CVE-2014-2941date:2014-08-15T11:15:42.997