PT-2019-13702 · Opengear · Opengear Console Server Firmware

Publicado

2019-07-31

·

Atualizado

2019-08-07

·

CVE-2019-14456

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Opengear console server firmware versions prior to 4.5.0
Description The issue is related to a stored XSS vulnerability in the serial port logging feature. If a malicious user sends crafted text to a serial port with logging enabled, the text will be replayed when the logs are viewed. Exploitation requires access to the serial port and/or console server.
Recommendations For Opengear console server firmware versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider disabling serial port logging until a patch is available. Restrict access to the serial port and console server to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14456

Produtos afetados

Opengear Console Server Firmware