Impact
Satell Netco Design versions below 2.1.7 are vulnerable to a stored cross‑site scripting flaw that allows an authenticated user with Network Operator privileges to inject untrusted data into the system. The stored data is rendered unmodified into web interfaces, causing arbitrary JavaScript to run in the browsers of any user who views the affected content. Because the code executes with the victim’s privileges, it can interact with the application, steal session tokens, or perform other malicious actions inside the browser.
Affected Systems
All deployments of Satel Netco Design running a version older than 2.1.7 are affected. The vendor identifies the vulnerable products as Satel Netco Design and recommends updating to version 2.1.7 or later.
Risk and Exploitability
With a CVSS score of 8.5, the vulnerability is rated high severity. The EPSS score is not available, suggesting insufficient public data on exploit frequency, and the issue has not yet been listed in CISA’s KEV catalog. The flaw requires authenticated access with Network Operator level rights, which implies that an insider or attacker who has already compromised an internal account can exploit the flaw. Once the content is viewed, arbitrary client‑side code runs, compromising confidentiality, integrity, and availability of the victim’s browser session. Hence the risk to organizations relying on Satel Netco Design is significant for systems where privileged users are not properly vetted.
OpenCVE Enrichment