Vulnerability Description
Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell built-in commands, as demonstrated by the "set ship name" command. This is similar to a Cross Protocol Injection with SNMP.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cobham | Sea Tel 116 Firmware | 222429 |
| Cobham | Sea Tel 116 | - |
Related Weaknesses (CWE)
References
- http://misteralfa-hack.blogspot.cl/2018/01/seatelcobham-terminales-satelitales.hExploitThird Party Advisory
- http://misteralfa-hack.blogspot.cl/2018/01/seatelcobham-terminales-satelitales.hExploitThird Party Advisory
FAQ
What is CVE-2018-5071?
CVE-2018-5071 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Persistent XSS exists in the web server on Cobham Sea Tel 116 build 222429 satellite communication system devices: remote attackers can inject malicious JavaScript code using the device's TELNET shell...
How severe is CVE-2018-5071?
CVE-2018-5071 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-5071?
Check the references section above for vendor advisories and patch information. Affected products include: Cobham Sea Tel 116 Firmware, Cobham Sea Tel 116.