Improper Firmware Signature Verification in Cobham Devices
CVE-2014-0328
Currently unrated
What is CVE-2014-0328?
The ThraneLINK protocol used in Cobham devices lacks adequate checks for firmware signatures, enabling potential attackers with physical or terminal access to exploit this flaw. By sending specially crafted SNMP requests and corresponding TFTP responses, malicious actors could execute arbitrary code on affected devices, putting system integrity at risk. Appropriate security measures should be taken to mitigate this vulnerability.
