漏洞信息详情
Sierra Wireless AirLink ES450 跨站脚本漏洞
漏洞简介
Sierra Wireless AirLink ES450是加拿大Sierra Wireless公司的一款蜂窝网络调制解调器设备。
使用4.9.3版本固件的Sierra Wireless AirLink ES450中的ACEManager ping_result.cgi功能存在跨站脚本漏洞,该漏洞源于WEB应用缺少对客户端数据的正确验证。攻击者可利用该漏洞执行客户端代码。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,详情请关注厂商主页:
https://www.sierrawireless.com/
参考网址
来源:BID
链接:http://www.securityfocus.com/bid/108147
来源:MISC
链接:http://packetstormsecurity.com/files/152650/Sierra-Wireless-AirLink-ES450-ACEManager-ping_result.cgi-Cross-Site-Scripting.html
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/~/media/support_downloads/airlink/docs/technical%20bulletin/swi-psa-2019-003%20-%20talos%20cves%20-%2030apr2019.ashx?la=en
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0747
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0748
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0752
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0750
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0746
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0754
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/reports/TALOS-2018-0751
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_reference_docs/technical-bulletin/sierra-wireless-technical-bulletin---swi-psa-2019-003/
来源:www.sierrawireless.com
链接:https://www.sierrawireless.com/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_reference_docs/release-notes/aleos-4-d-9-d-4-release-notes/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_reference_docs/release-notes/aleos-4-d-4-d-8-release-notes/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_reference_docs/release-notes/aleos-4-d-11-d-2-release-notes/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/rv50/rv50-firmware-list/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/mp70/mp70-firmware-list/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/ls300-firmware/ls300-firmware-list/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/gx450/gx450-firmware-list/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/gx400-firmware/gx400-firmware-list/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/es450/es450-firmware-package-list/
来源:source.sierrawireless.com
链接:https://source.sierrawireless.com/resources/airlink/software_downloads/es440-firmware/es440-firmware-list/
来源:talosintelligence.com
链接:https://talosintelligence.com/vulnerability_reports/TALOS-2018-0750
来源:www.nsfocus.net
链接:http://www.nsfocus.net/vulndb/47356
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/152650/Sierra-Wireless-AirLink-ES450-ACEManager-ping/result.cgi-Cross-Site-Scripting.html
来源:www.talosintelligence.com
链接:https://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0750
来源:www.us-cert.gov
链接:https://www.us-cert.gov/ics/advisories/ICSA-19-122-03
来源:www.securityfocus.com
链接:https://www.securityfocus.com/bid/108147
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2018-4065
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2019.1530.2/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/80158
来源:ics-cert.us-cert.gov
链接:https://ics-cert.us-cert.gov/advisories/ICSA-19-122-03
受影响实体
暂无
补丁
- Sierra Wireless AirLink ES450 跨站脚本漏洞的修复措施<!--2019-4-25-->
还没有评论,来说两句吧...