PT-2019-13702 · Opengear · Opengear Console Server Firmware

Published

2019-07-31

·

Updated

2019-08-07

·

CVE-2019-14456

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Opengear console server firmware versions prior to 4.5.0
Description The issue is related to a stored XSS vulnerability in the serial port logging feature. If a malicious user sends crafted text to a serial port with logging enabled, the text will be replayed when the logs are viewed. Exploitation requires access to the serial port and/or console server.
Recommendations For Opengear console server firmware versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider disabling serial port logging until a patch is available. Restrict access to the serial port and console server to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14456

Affected Products

Opengear Console Server Firmware