Improper Firmware Signature Verification in Cobham Devices
CVE-2014-0328

Currently unrated

What is CVE-2014-0328?

The ThraneLINK protocol used in Cobham devices lacks adequate checks for firmware signatures, enabling potential attackers with physical or terminal access to exploit this flaw. By sending specially crafted SNMP requests and corresponding TFTP responses, malicious actors could execute arbitrary code on affected devices, putting system integrity at risk. Appropriate security measures should be taken to mitigate this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.