Vulnerability Description
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cobham | Satcom Sailor 800 Firmware | - |
| Cobham | Satcom Sailor 800 | - |
| Cobham | Satcom Sailor 900 Firmware | - |
| Cobham | Satcom Sailor 900 | - |
Related Weaknesses (CWE)
References
- https://cyberskr.com/blog/cobham-satcom-800-900.htmlThird Party Advisory
- https://gist.github.com/CyberSKR/fe21b920c8933867ea262a325d37f03bThird Party Advisory
- https://cyberskr.com/blog/cobham-satcom-800-900.htmlThird Party Advisory
- https://gist.github.com/CyberSKR/fe21b920c8933867ea262a325d37f03bThird Party Advisory
FAQ
What is CVE-2018-19394?
CVE-2018-19394 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration ...
How severe is CVE-2018-19394?
CVE-2018-19394 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19394?
Check the references section above for vendor advisories and patch information. Affected products include: Cobham Satcom Sailor 800 Firmware, Cobham Satcom Sailor 800, Cobham Satcom Sailor 900 Firmware, Cobham Satcom Sailor 900.