Arbitrary Code Execution Vulnerability in Cobham SAILOR VSAT Ku v.164B019
CVE-2023-44852

8.2HIGH

Key Information:

Vendor

Cobham

Vendor
CVE Published:
12 April 2024

What is CVE-2023-44852?

The vulnerability presents a Cross Site Scripting (XSS) risk within the Cobham SAILOR VSAT Ku software version 164B019. This issue arises from an inadequate validation of user input within the c_set_traps_decode function in the acu_web file. A remote attacker can exploit this flaw by injecting a crafted script, leading to the execution of arbitrary code. This vulnerability underscores significant security concerns for users of the affected product, requiring immediate attention to safeguard against potential exploits.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.