CVE-2019-17667

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
17/10/2019
Last modified:
02/01/2026

Description

Comtech H8 Heights Remote Gateway 2.5.1 devices allow XSS and HTML injection via the Site Name (aka SiteName) field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:comtech:h8_heights_remote_gateway_firmware:2.5.1:*:*:*:*:*:*:*
cpe:2.3:h:comtech:h8_heights_remote_gateway:-:*:*:*:*:*:*:*