← Back

CVE-2019-18265

nvd nist
Published: Nov 30, 2022Modified: Jun 17, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.

Affected (5)

Dasdec Ii Firmware
One Net Se Firmware
Dasdec I Firmware
One Net Firmware
Dasdec Iii Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1
Running on/withPlatform Versions
Digitalalertsystems
Dasdec Ii
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1
Running on/withPlatform Versions
Digitalalertsystems
One Net Se
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1
Running on/withPlatform Versions
Digitalalertsystems
Dasdec I
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1
Running on/withPlatform Versions
Digitalalertsystems
One Net
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 4.1
Running on/withPlatform Versions
Digitalalertsystems
Dasdec Iii
All versions

References (2)

Source: ics-cert@hq.dhs.gov
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory

Timeline

No history available yet.