Description
Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point to inject malicious JavaScript into the payload of web traffics, potentially leading to session hijacking and denial-of-service (DoS).
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected products
- Alcatel-Lucent / OmniAccess StellarAP1100 AWOS versions 5.0.2 GA and earlier – AP1100 AWOS versions 5.0.2 GA and earlier
- Alcatel-Lucent / OmniAccess StellarAP1200 AWOS versions 5.0.2 GA and earlier – AP1200 AWOS versions 5.0.2 GA and earlier
- Alcatel-Lucent / OmniAccess StellarAP1300 AWOS versions 5.0.2 GA and earlier – AP1300 AWOS versions 5.0.2 GA and earlier
- Alcatel-Lucent / OmniAccess StellarAP1400 AWOS versions 5.0.2 GA and earlier – AP1400 AWOS versions 5.0.2 GA and earlier
- Alcatel-Lucent / OmniAccess StellarAP1500 AWOS versions 5.0.2 GA and earlier – AP1500 AWOS versions 5.0.2 GA and earlier