漏洞信息详情
Advantech Spectre RT ERT351 firmware 跨站脚本漏洞
漏洞简介
Advantech Spectre RT ERT351 firmware(Advantech Spectre RT ERT351 firmware)是美国Advantech公司的一个路由器提供网络路由功能
Spectre RT ERT351 firmware Versions 5.1.3 and prior 存在跨站脚本漏洞,该漏洞源于不会在错误响应中消除特殊字符,从而允许攻击者使用反映的XSS攻击。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://ep.advantech-bb.cz/support/router-models/download/511/sa-2021-01-fw-5.1.3-and-older-en.pdf
参考网址
来源:MISC
链接:https://ep.advantech-bb.cz/support/router-models/download/511/sa-2021-01-fw-5.1.3-and-older-en.pdf
来源:MISC
链接:https://us-cert.cisa.gov/ics/advisories/icsa-21-054-03
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.0680
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-18233
来源:us-cert.cisa.gov
链接:https://us-cert.cisa.gov/ics/advisories/icsa-21-054-03
受影响实体
暂无
补丁
- Advantech Spectre RT ERT351 firmware 安全漏洞的修复措施<!--2021-2-23-->
还没有评论,来说两句吧...