Researchers warn of two critical vulnerabilities in global satellite telecommunications company Inmarsat s SATCOM systems. The vulnerabilities impact thousands of customers running the newest version of its AmosConnect platform, typically found on maritime sea vessels, according to researchers at IOActive. One of the vulnerabilities is a blind SQL injection flaw found in the login form that allows attackers already on the network to access user credentials of other users. The second bug (CVE-2017-3222) is tied to hard-coded credentials found in AmosConnect 8 that allow remote attackers to gain full administrative privileges.
Source: https://threatpost.com/two-critical-vulnerabilities-found-in-inmarsats-satcom-systems/128632/

