Improper Input Validation in Advantech Spectre RT Industrial Routers
CVE-2019-18233

6.1MEDIUM

What is CVE-2019-18233?

The Advantech Spectre RT Industrial Routers, specifically the ERT351 version 5.1.3 and earlier, are susceptible to reflected Cross-Site Scripting (XSS) attacks. This vulnerability arises from the lack of proper neutralization of special characters in the error responses generated by the device. An attacker can exploit this flaw to execute malicious scripts in the context of a user's browser, leading to potential unauthorized access and data compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.