CVE-2018-19694

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
21/03/2019
Last modified:
25/03/2019

Description

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:hms-networks:netbiter_ws100_firmware:*:*:*:*:*:*:*:* 3.30.5 (including)
cpe:2.3:h:hms-networks:netbiter_ws100:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ws200_firmware:*:*:*:*:*:*:*:* 3.30.4 (including)
cpe:2.3:h:hms-networks:netbiter_ws200:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ec150_firmware:*:*:*:*:*:*:*:* 1.40.0 (including)
cpe:2.3:h:hms-networks:netbiter_ec150:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ec250_firmware:*:*:*:*:*:*:*:* 1.40.0 (including)
cpe:2.3:h:hms-networks:netbiter_ec250:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc310_firmware:*:*:*:*:*:*:*:* 3.30.5 (including)
cpe:2.3:h:hms-networks:netbiter_lc310:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc310_thingworx_firmware:*:*:*:*:*:*:*:* 2.00.07 (including)
cpe:2.3:h:hms-networks:netbiter_lc310_thingworx:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc350_firmware:*:*:*:*:*:*:*:* 2.00.07 (including)
cpe:2.3:h:hms-networks:netbiter_lc350:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc350_thingworx_firmware:*:*:*:*:*:*:*:* 2.00.07 (including)