Persistent XSS Vulnerability in Cobham Satcom Sailor 800 and 900 Devices
CVE-2018-19394

4.8MEDIUM

Key Information:

Vendor

Cobham

Vendor
CVE Published:
15 March 2019

What is CVE-2018-19394?

Cobham Satcom Sailor 800 and 900 devices are vulnerable to a persistent Cross-Site Scripting (XSS) flaw that can be exploited if an attacker gains administrative access. This vulnerability allows the attacker to modify the device's configuration file by inserting malicious XSS payloads into fields like the Satellite name. Once the altered configuration file is restored, it executes the payload, compromising the integrity and security of the device. This poses significant risks, especially in applications where these devices are used.

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.