Arbitrary Code Execution Vulnerability in Cobham SAILOR VSAT Ku v.164B019
CVE-2023-44855

6.5MEDIUM

Key Information:

Vendor

Cobham

Vendor
CVE Published:
12 April 2024

What is CVE-2023-44855?

A Cross Site Scripting (XSS) vulnerability exists in Cobham SAILOR VSAT Ku version 164B019, which enables remote attackers to inject and execute arbitrary code. This vulnerability pertains to the processing of parameters such as rdiag, sender, and recipients within the sub_219C4 function located in the acu_web file. Exploitation of this flaw can result in unauthorized actions on behalf of legitimate users and may lead to wider system compromises.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.