MEDIUM · 6.1

CVE-2018-19694

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

Vulnerability Description

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Hms-NetworksNetbiter Ws100 Firmware<= 3.30.5
Hms-NetworksNetbiter Ws100-
Hms-NetworksNetbiter Ws200 Firmware<= 3.30.4
Hms-NetworksNetbiter Ws200-
Hms-NetworksNetbiter Ec150 Firmware<= 1.40.0
Hms-NetworksNetbiter Ec150-
Hms-NetworksNetbiter Ec250 Firmware<= 1.40.0
Hms-NetworksNetbiter Ec250-
Hms-NetworksNetbiter Lc310 Firmware<= 3.30.5
Hms-NetworksNetbiter Lc310-
Hms-NetworksNetbiter Lc310 Thingworx Firmware<= 2.00.07
Hms-NetworksNetbiter Lc310 Thingworx-
Hms-NetworksNetbiter Lc350 Firmware<= 2.00.07
Hms-NetworksNetbiter Lc350-
Hms-NetworksNetbiter Lc350 Thingworx Firmware<= 2.00.07
Hms-NetworksNetbiter Lc350 Thingworx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-19694?

CVE-2018-19694 is a vulnerability with a CVSS score of 6.1 (MEDIUM). HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.

How severe is CVE-2018-19694?

CVE-2018-19694 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-19694?

Check the references section above for vendor advisories and patch information. Affected products include: Hms-Networks Netbiter Ws100 Firmware, Hms-Networks Netbiter Ws100, Hms-Networks Netbiter Ws200 Firmware, Hms-Networks Netbiter Ws200, Hms-Networks Netbiter Ec150 Firmware.