Vulnerability Details CVE-2018-19394
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 46.4%
CVSS Severity
CVSS v3 Score 4.8
CVSS v2 Score 3.5
Products affected by CVE-2018-19394
-
cpe:2.3:h:cobham:satcom_sailor_800:-
-
cpe:2.3:h:cobham:satcom_sailor_900:-
-
cpe:2.3:o:cobham:satcom_sailor_800_firmware:-
-
cpe:2.3:o:cobham:satcom_sailor_900_firmware:-