CVE-2019-18233 Information

Description

In Advantech Spectre RT Industrial Routers ERT351 5.1.3 and prior the affected product does not neutralize special characters in the error response allowing attackers to use a reflected XSS attack.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://ep.advantech-bb.cz/support/router-models/download/511/sa-2021-01-fw-5.1.3-and-older-en.pdf https://us-cert.cisa.gov/ics/advisories/icsa-21-054-03

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: