An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution.
2019-12-18T20:15:16.383
2024-11-21T04:32:56.590
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ge | s2020_firmware | ≤ 07a03 | Yes |
Hardware | ge | s2020 | - | No |
Operating System | ge | s2020g_firmware | ≤ 07a03 | Yes |
Hardware | ge | s2020g | - | No |