Vulnerability Description
An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause reflected javascript code execution, resulting in the execution of javascript code running on the victim's browser. An attacker can get a victim to click a link, or embedded URL, that redirects to the reflected cross-site scripting vulnerability to trigger this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sierrawireless | Airlink Es450 Firmware | 4.9.3 |
| Sierrawireless | Airlink Es450 | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/152650/Sierra-Wireless-AirLink-ES450-ACEMan
- http://www.securityfocus.com/bid/108147
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0750ExploitThird Party Advisory
- http://packetstormsecurity.com/files/152650/Sierra-Wireless-AirLink-ES450-ACEMan
- http://www.securityfocus.com/bid/108147
- https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03
- https://talosintelligence.com/vulnerability_reports/TALOS-2018-0750ExploitThird Party Advisory
FAQ
What is CVE-2018-4065?
CVE-2018-4065 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An exploitable cross-site scripting vulnerability exists in the ACEManager ping_result.cgi functionality of Sierra Wireless AirLink ES450 FW 4.9.3. A specially crafted HTTP ping request can cause refl...
How severe is CVE-2018-4065?
CVE-2018-4065 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-4065?
Check the references section above for vendor advisories and patch information. Affected products include: Sierrawireless Airlink Es450 Firmware, Sierrawireless Airlink Es450.