CVE-2018-19394
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
Los dispositivos Cobham Satcom Sailor 800 y 900 contenían Cross-Site Scripting (XSS) persistente, que requería acceso administrativo para su explotación. La vulnerabilidad era explotable adquiriendo una copia del archivo de configuración del dispositivo, insertando una carga útil XSS en un campo relevante (por ejemplo, "Satellite name") y, después, recuperando el archivo de configuración malicioso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-20 CVE Reserved
- 2019-03-15 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://cyberskr.com/blog/cobham-satcom-800-900.html | Third Party Advisory | |
https://gist.github.com/CyberSKR/fe21b920c8933867ea262a325d37f03b | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cobham Search vendor "Cobham" | Satcom Sailor 800 Firmware Search vendor "Cobham" for product "Satcom Sailor 800 Firmware" | - | - |
Affected
| in | Cobham Search vendor "Cobham" | Satcom Sailor 800 Search vendor "Cobham" for product "Satcom Sailor 800" | - | - |
Safe
|
Cobham Search vendor "Cobham" | Satcom Sailor 900 Firmware Search vendor "Cobham" for product "Satcom Sailor 900 Firmware" | - | - |
Affected
| in | Cobham Search vendor "Cobham" | Satcom Sailor 900 Search vendor "Cobham" for product "Satcom Sailor 900" | - | - |
Safe
|