CVE-2019-19393 describes a persistent cross-site scripting (XSS) vulnerability in the web application of Rittal CMC PU III 7030.000 V3.00 devices, specifically firmware versions V3.11.00_2 to V3.15.70_4. An attacker can inject malicious HTML and client-side scripts into the system configurations page due to improper input sanitization, which then executes for any user accessing the interface. This medium-severity vulnerability (CVSS 6.1) requires access to the web management interface, either through valid credentials or a hijacked session, and could lead to content modification or information theft. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.11.00_2, <= 3.15.70_4CPE matchmatch criteria | cpe:2.3:o:rittal:cmc_pu_iii_7030.000_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.