An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-8060 An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T01:47:14.086Z

Reserved: 2019-10-22T00:00:00

Link: CVE-2019-18267

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-18T20:15:16.383

Modified: 2024-11-21T04:32:56.590

Link: CVE-2019-18267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses