Back to Database
Status published
Medium
CVE-2018-19391
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained...
Vulnerability Description
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-19391
Credits & Attribution
No credits recorded in the NVD database.
References
More from cobham
View All →CVE-2019-16320
Cobham Sea Tel v170 224521 through v194 225444 devices allow...
Medium
5.3
CVE-2018-5728
Cobham Sea Tel 121 build 222701 devices allow remote attackers...
Medium
5.3
CVE-2018-5267
Cobham Sea Tel 121 build 222701 devices allow remote attackers...
Critical
9.8
CVE-2018-5266
Cobham Sea Tel 121 build 222701 devices allow remote attackers...
High
7.5
CVE-2018-5071
Persistent XSS exists in the web server on Cobham Sea...
Medium
5.4
Affected Vendor
cobham
View all reports →Affected Software
satcom sailor 250 firmware, satcom sailor 500 firmware
Vulnerable Versions:
0
Timeline
Official Publish:
March 15th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.