CWE
79 352
Advisory Published
Updated

CVE-2019-18267: XSS

First published: Wed Dec 18 2019(Updated: )

An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Ge S2020 Firmware<=07a03
GE S2020
Ge S2020g Firmware<=07a03
Ge S2020g

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the vulnerability ID?

    The vulnerability ID is CVE-2019-18267.

  • What is the severity of CVE-2019-18267?

    The severity of CVE-2019-18267 is medium with a severity score of 5.4.

  • Which products are affected by CVE-2019-18267?

    GE S2020/S2020G Fast Switch 61850 Versions 07A03 and prior are affected by CVE-2019-18267.

  • How does CVE-2019-18267 work?

    An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response, leading to a potential stored cross-site scripting (XSS) vulnerability.

  • Is there a fix available for CVE-2019-18267?

    To mitigate this vulnerability, GE S2020/S2020G Fast Switch 61850 users should update to a version later than 07A03 and follow any recommended security practices provided by the vendor.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203