CISA

Satel Netco Design

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessive system resources, enumerate files, create or modify files, and potentially execute arbitrary code.

The following versions of Satel Netco Design are affected:

Satel Netco Design

Vendor

Equipment

Satel

Satel Netco Design

3 Vulnerabilities

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Inefficient Regular Expression Complexity, Relative Path Traversal

Critical Infrastructure Sectors: Communications

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Finland

Satel Netco Design versions prior to v2.1.7 contains a stored cross site scripting vulnerability. An authenticated user with Network Operator privileges could store untrusted content that is rendered without adequate neutralization...