S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 29, 2024

CVE-2019-11370 Scanner

CVE-2019-11370 scanner - Cross-Site Scripting (XSS) vulnerability in Carel pCOWeb

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-11370
5.4
CVSS

Stored XSS was discovered in Carel pCOWeb prior to B1.2.4, as demonstrated by the config/pw_snmp.html "System contact" field.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Carel pCOWeb is a product used for monitoring and remotely controlling HVAC (heating, ventilation and air conditioning) systems. It provides real-time monitoring, dynamic management, and remote programming of HVAC systems, giving the user full control over their equipment. The pCOWeb is widely used in various industries, including data centers, hospitals, commercial buildings, and pharmaceutical companies, ensuring efficient energy consumption and comfortable indoor environments.

CVE-2019-11370 is a critical vulnerability discovered in the Carel pCOWeb prior to B1.2.4. The vulnerability affects the config/pw_snmp.html "System contact" field, which can be exploited through a stored cross-site scripting (XSS) attack. This attack allows an attacker to inject malicious code into the web page, which can lead to the stealing of sensitive data, such as passwords or personal information, or a complete takeover of the HVAC system.

If exploited, the CVE-2019-11370 vulnerability can have severe consequences for the organization using the pCOWeb, including data theft, loss of control over the HVAC system, or a complete system shutdown. This can cause significant financial and reputational damage, as well as jeopardizing the safety and well-being of the people using the facility.

Thanks to the pro features of the s4e.io platform, organizations can easily and quickly identify vulnerabilities in their digital assets. With a comprehensive vulnerability scanning and reporting system, S4E offers robust solutions for identifying and mitigating security risks, ensuring the safety and security of your organization's digital assets. Don't wait until it's too late – protect your systems today with S4E.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended to take the following precautions:

  • Update the pCOWeb firmware to the latest version (B1.2.4)
  • Limit the access to the pCOWeb interface to authorized personnel only
  • Use strong and unique passwords for all accounts on the pCOWeb
  • Regularly monitor the pCOWeb activity logs for any suspicious activity
  • Implement a web application firewall to detect and prevent XSS attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.