CVE-2018-19694

HMS Industrial Networks Netbiter WS100 3.30.5 devices and previous have reflected XSS in the login form.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_ws100:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ws100_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_ws200:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ws200_firmware:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_ec150:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ec150_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_ec250:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_ec250_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_lc310:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc310_firmware:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_lc310_thingworx:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc310_thingworx_firmware:*:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_lc350:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc350_firmware:*:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:h:hms-networks:netbiter_lc350_thingworx:-:*:*:*:*:*:*:*
cpe:2.3:o:hms-networks:netbiter_lc350_thingworx_firmware:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2019-03-21 16:00

Updated : 2019-03-25 12:33


NVD link : CVE-2018-19694

Mitre link : CVE-2018-19694

CVE.ORG link : CVE-2018-19694


JSON object : View

Products Affected

hms-networks

  • netbiter_ws100_firmware
  • netbiter_ws100
  • netbiter_ec150_firmware
  • netbiter_ec250_firmware
  • netbiter_ec150
  • netbiter_ws200
  • netbiter_lc310_thingworx_firmware
  • netbiter_lc350_thingworx_firmware
  • netbiter_lc350
  • netbiter_ec250
  • netbiter_ws200_firmware
  • netbiter_lc350_thingworx
  • netbiter_lc310
  • netbiter_lc350_firmware
  • netbiter_lc310_firmware
  • netbiter_lc310_thingworx
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')