PT-2019-13702 · Opengear · Opengear Console Server Firmware
Published
2019-07-31
·
Updated
2019-08-07
·
CVE-2019-14456
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Opengear console server firmware versions prior to 4.5.0
Description
The issue is related to a stored XSS vulnerability in the serial port logging feature. If a malicious user sends crafted text to a serial port with logging enabled, the text will be replayed when the logs are viewed. Exploitation requires access to the serial port and/or console server.
Recommendations
For Opengear console server firmware versions prior to 4.5.0, update to version 4.5.0 or later to resolve the issue. As a temporary workaround, consider disabling serial port logging until a patch is available. Restrict access to the serial port and console server to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opengear Console Server Firmware