Remote Attacker Can Execute Arbitrary Code via Crafted Script in Cobham SAILOR VSAT Ku v.164B019
CVE-2023-44857

8.1HIGH

Key Information:

Vendor

Cobham

Vendor
CVE Published:
12 April 2024

What is CVE-2023-44857?

A vulnerability exists in the Cobham SAILOR VSAT Ku software version 164B019, which enables remote attackers to execute arbitrary code. This is facilitated through a specially crafted script that targets the sub_21D24 function in the acu_web component. The exploitation of this vulnerability can lead to unauthorized access and control over affected devices, raising significant security concerns for users relying on this technology.

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.