Description
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-8060 | An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution. |
References
| Link | Providers |
|---|---|
| https://www.us-cert.gov/ics/advisories/icsa-19-351-01 |
|
History
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T01:47:14.086Z
Reserved: 2019-10-22T00:00:00.000Z
Link: CVE-2019-18267
No data.
Status : Modified
Published: 2019-12-18T20:15:16.383
Modified: 2024-11-21T04:32:56.590
Link: CVE-2019-18267
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD