{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-05T16:27:28.352","vulnerabilities":[{"cve":{"id":"CVE-2019-18267","sourceIdentifier":"ics-cert@hq.dhs.gov","published":"2019-12-18T20:15:16.383","lastModified":"2026-06-17T02:24:43.600","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a stored cross-site scripting vulnerability that may allow session hijacking, disclosure of sensitive data, cross-site request forgery (CSRF) attacks, and remote code execution."},{"lang":"es","value":"Se detectó un problema en GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versiones 07A03 y anteriores. Un atacante puede inyectar Javascript arbitrario en una petición HTTP especialmente diseñada que puede ser reflejada en la respuesta HTTP. El dispositivo también es susceptible a una vulnerabilidad de tipo cross-site scripting almacenado que puede permitir un secuestro de sesión, una divulgación de datos confidenciales, ataques de tipo cross-site request forgery (CSRF) y una ejecución de código remota."}],"affected":[{"source":"ics-cert@hq.dhs.gov","affectedData":[{"vendor":"n/a","product":"GE S2020/S2020G Fast Switch 61850","versions":[{"version":"S2020/S2020G Fast Switch 61850 Versions 07A03 and prior","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","baseScore":5.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":2.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"ics-cert@hq.dhs.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:s2020_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"07a03","matchCriteriaId":"C3616651-CFB3-4E75-BDB9-CA7F571A1DA3"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:s2020:-:*:*:*:*:*:*:*","matchCriteriaId":"246DAD44-F752-4BE4-9475-ADFAA70BEB44"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:ge:s2020g_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"07a03","matchCriteriaId":"AD846435-648D-447F-93BA-15F83AD792DA"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:ge:s2020g:-:*:*:*:*:*:*:*","matchCriteriaId":"88390636-707A-4B0D-973E-4EB0495E0B13"}]}]}],"references":[{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-351-01","source":"ics-cert@hq.dhs.gov","tags":["Third Party Advisory","US Government Resource"]},{"url":"https://www.us-cert.gov/ics/advisories/icsa-19-351-01","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]}]}}]}