IDC SFX2100 Satellite Receivers World-Writable DNS Configuration Vulnerability

Vulnerability

A vulnerability exists in the IDC SFX2100 satellite receivers, which are used by organizations such as the US Department of Defense and the European Space Agency. The issue arises from the receivers setting the '/etc/resolv.conf' file to be world-writable, allowing any local user to tamper with the DNS resolver. This could lead to unauthorized redirection of network communications, facilitate man-in-the-middle attacks, and cause denial-of-service conditions.

Impact

Exploitation of this vulnerability allows for unauthorized modification of the DNS resolver configuration, potentially leading to redirected network communications, man-in-the-middle attacks, and denial-of-service conditions.

Reproduction

The vulnerability can be reproduced by accessing the SFX2100 receiver and verifying the permissions of the '/etc/resolv.conf' file, which is set to be world-writable. This can be done by using the 'stat' command to check the file's permission settings.

Added: Mar 5, 2026, 2:20 AM
Updated: Mar 5, 2026, 7:50 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.6
exploitability
4.2
remediation
0.0
relevance
3.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.