CVE-2019-16104: XSS
Published Sep 8, 2019
·Updated
Silver Peak EdgeConnect SD-WAN before 8.1.7.x has reflected XSS via the rest/json/configdb/download/ PATHINFO.
Affected Software
2 affected components
Silver-peak Unity Edgeconnect Sd-wan Firmware=8.1.4.9_65644
Silver-peak Unity Edgeconnect Sd-wan
Event History
Sep 8, 2019
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
Description
Frequently Asked Questions
1
What is CVE-2019-16104?
CVE-2019-16104 is a vulnerability in Silver Peak EdgeConnect SD-WAN before 8.1.7.x that allows for reflected XSS attacks via the rest/json/configdb/download/ PATH_INFO.
2
How severe is CVE-2019-16104?
CVE-2019-16104 has a severity keyword of 'medium' and a severity value of 6.1 on the CVSS scale.
3
What software versions are affected by CVE-2019-16104?
Silver Peak EdgeConnect SD-WAN firmware versions before 8.1.7.x, specifically version 8.1.4.9_65644, are affected by CVE-2019-16104.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-16104?
The Common Weakness Enumeration (CWE) ID for CVE-2019-16104 is CWE-79.
5
Is Silver Peak Unity EdgeConnect SD-WAN vulnerable to CVE-2019-16104?
No, Silver Peak Unity EdgeConnect SD-WAN is not vulnerable to CVE-2019-16104.