Cross-Site Scripting Vulnerability in Sierra Wireless AirLink ES450
CVE-2018-4065

6.1MEDIUM

Key Information:

Vendor
CVE Published:
6 May 2019

What is CVE-2018-4065?

A cross-site scripting vulnerability affects the ACEManager ping_result.cgi functionality of the Sierra Wireless AirLink ES450 running firmware version 4.9.3. This flaw allows attackers to craft a malicious HTTP ping request that can lead to reflected JavaScript code execution in the victim's browser. If the victim interacts with a manipulated link or embedded URL, it can trigger the execution of potentially harmful scripts, placing user data and security at risk.

Affected Version(s)

Sierra Wireless Sierra Wireless AirLink ES450 FW 4.9.3

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.