CVE-2019-10933 - CVE House
Back to Database
Status published Medium CVE-2019-10933

A vulnerability has been identified in Spectrum Power 3 (Corporate...

Vulnerability Description

A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All versions < v5.50), Spectrum Power 7 (Corporate User Interface) (All versions <= v2.20). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user does not need to be logged into the web interface in order for the exploitation to succeed.At the stage of publishing this security advisory no public exploitation is known.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10933

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Spectrum Power 3 (Corporate User Interface), Spectrum Power 4 (Corporate User Interface), Spectrum Power 5 (Corporate User Interface), Spectrum Power 7 (Corporate User Interface)
Vulnerable Versions:
All versions <= v3.11, Version v4.75, All versions < v5.50, All versions <= v2.20

Timeline

Official Publish: July 11th, 2019
Last Modified: August 4th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)