PT-2019-13702 · Opengear · Opengear Console Server Firmware
Publicado
2019-07-31
·
Atualizado
2019-08-07
·
CVE-2019-14456
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opengear console server firmware versions prior to 4.5.0
Description
The issue is related to a stored XSS vulnerability in the serial port logging feature. If a malicious user sends crafted text to a serial port with logging enabled, the text will be replayed when the logs are viewed. Exploitation requires access to the serial port and/or console server.
Recommendations
For Opengear console server firmware versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider disabling serial port logging until a patch is available. Restrict access to the serial port and console server to minimize the risk of exploitation.
Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Opengear Console Server Firmware