CVE-2018-19394

MEDIUM

Cobham Satcom Sailor 800 and 900 Firmware - Authenticated Stored Cross-Site Scripting via Configuration File Restore

Title source: llm
STIX 2.1

Description

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://cyberskr.com/blog/cobham-satcom-800-900.html

Scores

CVSS v3 4.8
EPSS 0.0069
EPSS Percentile 49.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
cobham/satcom_sailor_800_firmware
cobham/satcom_sailor_900_firmware
Published Mar 15, 2019
Tracked Since Feb 18, 2026