VYPR
Unrated severityNVD Advisory· Published Sep 8, 2019· Updated Aug 5, 2024

CVE-2019-16104

CVE-2019-16104

Description

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has a reflected XSS vulnerability via the rest/json/configdb/download/ PATH_INFO.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Silver Peak EdgeConnect SD-WAN before 8.1.7.x has a reflected XSS vulnerability via the rest/json/configdb/download/ PATH_INFO.

Vulnerability

The Silver Peak EdgeConnect SD-WAN appliance, versions prior to 8.1.7.x, contains a reflected Cross-Site Scripting (XSS) vulnerability in the rest/json/configdb/download/ endpoint. This issue is documented in [1]. An attacker can inject arbitrary JavaScript code through the PATH_INFO parameter, which is then reflected back to the user without proper sanitization or encoding.

Exploitation

An attacker can exploit this vulnerability by crafting a malicious URL that includes the XSS payload in the PATH_INFO segment of the request to the vulnerable endpoint. The attacker does not require authentication, but must convince a victim user to click on the crafted link (user interaction required). The payload is executed in the browser of the victim when the crafted URL is accessed, within the security context of the target application [1].

Impact

Successful exploitation allows the attacker to execute arbitrary JavaScript in the victim's browser, within the origin of the EdgeConnect SD-WAN management interface. This can lead to session hijacking, credential theft, or other actions that the victim can perform on the application, compromising the confidentiality, integrity, and availability of the affected system [1].

Mitigation

The vulnerability is fixed in Silver Peak EdgeConnect SD-WAN release 8.1.7.x and later. Users should upgrade to a patched version. If upgrading is not possible, restrict network access to the management interface to trusted users only and enable web application firewall (WAF) rules that filter malicious input in PATH_INFO [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.