CVE-2019-18267

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
18/12/2019
Last modified:
07/01/2020

Description

An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ge:s2020_firmware:*:*:*:*:*:*:*:* 07a03 (including)
cpe:2.3:h:ge:s2020:-:*:*:*:*:*:*:*
cpe:2.3:o:ge:s2020g_firmware:*:*:*:*:*:*:*:* 07a03 (including)
cpe:2.3:h:ge:s2020g:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools