CVE-2019-9532

HIGH

Cobham EXPLORER 710 <1.07 - Info Disclosure

Title source: llm
STIX 2.1

Description

The web application portal of the Cobham EXPLORER 710, firmware version 1.07, sends the login password in cleartext. This could allow an unauthenticated, local attacker to intercept the password and gain access to the portal.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
https://kb.cert.org/vuls/id/719689/

Scores

CVSS v3 7.8
EPSS 0.0022
EPSS Percentile 11.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-319
Status published
Products (1)
cobham/explorer_710_firmware 1.07
Published Oct 10, 2019
Tracked Since Feb 18, 2026