Security readout for executives and security teams
Plain-English summary
CVE-2018-19394 is a stored cross-site scripting issue reported in Cobham Satcom Sailor 800 and 900 devices. An administrator-level user could restore a modified configuration file that causes script content to persist in the management interface. Business urgency depends on whether these satellite communication devices are deployed and whether administrative access is tightly controlled.
Executive priority
Prioritize assessment if these terminals support critical maritime communications or are remotely administered. The issue is not evidenced as actively exploited, but configuration integrity and administrator access should be treated as operational controls.
Technical view
The source describes persistent XSS through device configuration restore. The reported path requires administrative access, possession or modification of a configuration file, and restoration of that file with unsafe content in a field such as a satellite name. No CVSS score, firmware range, patch version, or CWE mapping is provided in the bundle.
Likely exposure
Exposure is most likely in organizations operating Cobham Satcom Sailor 800 or 900 terminals with reachable administrative interfaces or weak configuration-file controls. Exact affected firmware versions are not supplied.
Exploitation context
The source bundle does not show active exploitation, and the CVE is not marked as CISA KEV. Exploitation is constrained by an administrator-access requirement and configuration restore workflow, but stored XSS can still affect trusted device-management sessions.
Researcher notes
Evidence is limited. The bundle identifies product family and attack condition but lacks version granularity, severity scoring, patch details, and independent exploitation confirmation. Treat affected-version and remediation conclusions as pending vendor confirmation.
Mitigation direction
- Check Cobham Satcom vendor guidance for affected firmware and fixes.
- Restrict administrative interface access to trusted management networks.
- Limit configuration export, editing, and restore privileges.
- Review restored configuration files before applying them.
- Monitor device administration activity for unexpected configuration changes.
Validation and detection
- Inventory Sailor 800 and 900 devices and record firmware versions.
- Confirm administrative interfaces are not exposed to untrusted networks.
- Review configuration backups for unexpected script-like content in text fields.
- Check change logs for recent configuration restore events.
- Verify vendor advisories or support channels for remediation status.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-19394 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://cyberskr.com/blog/cobham-satcom-800-900.htmlCVE reference · x_refsource_MISC
- https://gist.github.com/CyberSKR/fe21b920c8933867ea262a325d37f03bCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
