CVE-2018-19394
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
15/03/2019
Last modified:
15/03/2019
Description
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:cobham:satcom_sailor_800_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cobham:satcom_sailor_800:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:cobham:satcom_sailor_900_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:cobham:satcom_sailor_900:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



