LiveActive security incident?Get immediate response
CVE Record

CVE-2018-19394: Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to...

Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2018-19394 is a stored cross-site scripting issue reported in Cobham Satcom Sailor 800 and 900 devices. An administrator-level user could restore a modified configuration file that causes script content to persist in the management interface. Business urgency depends on whether these satellite communication devices are deployed and whether administrative access is tightly controlled.

Executive priority

Prioritize assessment if these terminals support critical maritime communications or are remotely administered. The issue is not evidenced as actively exploited, but configuration integrity and administrator access should be treated as operational controls.

Technical view

The source describes persistent XSS through device configuration restore. The reported path requires administrative access, possession or modification of a configuration file, and restoration of that file with unsafe content in a field such as a satellite name. No CVSS score, firmware range, patch version, or CWE mapping is provided in the bundle.

Likely exposure

Exposure is most likely in organizations operating Cobham Satcom Sailor 800 or 900 terminals with reachable administrative interfaces or weak configuration-file controls. Exact affected firmware versions are not supplied.

Exploitation context

The source bundle does not show active exploitation, and the CVE is not marked as CISA KEV. Exploitation is constrained by an administrator-access requirement and configuration restore workflow, but stored XSS can still affect trusted device-management sessions.

Researcher notes

Evidence is limited. The bundle identifies product family and attack condition but lacks version granularity, severity scoring, patch details, and independent exploitation confirmation. Treat affected-version and remediation conclusions as pending vendor confirmation.

Mitigation direction

  • Check Cobham Satcom vendor guidance for affected firmware and fixes.
  • Restrict administrative interface access to trusted management networks.
  • Limit configuration export, editing, and restore privileges.
  • Review restored configuration files before applying them.
  • Monitor device administration activity for unexpected configuration changes.

Validation and detection

  • Inventory Sailor 800 and 900 devices and record firmware versions.
  • Confirm administrative interfaces are not exposed to untrusted networks.
  • Review configuration backups for unexpected script-like content in text fields.
  • Check change logs for recent configuration restore events.
  • Verify vendor advisories or support channels for remediation status.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2018-19394 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.