First published: Wed Dec 18 2019(Updated: )
An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Ge S2020 Firmware | <=07a03 | |
GE S2020 | ||
Ge S2020g Firmware | <=07a03 | |
Ge S2020g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-18267.
The severity of CVE-2019-18267 is medium with a severity score of 5.4.
GE S2020/S2020G Fast Switch 61850 Versions 07A03 and prior are affected by CVE-2019-18267.
An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response, leading to a potential stored cross-site scripting (XSS) vulnerability.
To mitigate this vulnerability, GE S2020/S2020G Fast Switch 61850 users should update to a version later than 07A03 and follow any recommended security practices provided by the vendor.