Lucene search

K
ciscoCiscoCISCO-SA-20150406-CVE-2015-0690
HistoryApr 06, 2015 - 5:30 p.m.

Cisco Wireless LAN Controller HTML Help Cross-Site Scripting Vulnerability

2015-04-0617:30:53
tools.cisco.com
28

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

A vulnerability in the HTML help system of Cisco Wireless LAN Controller (WLC) devices could allow an unauthenticated, remote attacker conduct cross-site scripting attacks.

An unauthenticated, remote attacker who can convince a user of an affected system to follow a malicious link or visit an attacker-controlled web page could execute arbitrary HTML or script code in the security context of the affected site.

Cisco has confirmed the vulnerability; however, software updates are not available.

To exploit the vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.

Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Affected configurations

Vulners
Node
ciscowireless_lan_controllerMatch7.4
OR
ciscowireless_lan_controllerMatch7.6
OR
ciscowireless_lan_controllerMatch7.4.121.0
OR
ciscowireless_lan_controllerMatch7.6.100.0
VendorProductVersionCPE
ciscowireless_lan_controller7.4cpe:2.3:h:cisco:wireless_lan_controller:7.4:*:*:*:*:*:*:*
ciscowireless_lan_controller7.6cpe:2.3:h:cisco:wireless_lan_controller:7.6:*:*:*:*:*:*:*
ciscowireless_lan_controller7.4.121.0cpe:2.3:h:cisco:wireless_lan_controller:7.4.121.0:*:*:*:*:*:*:*
ciscowireless_lan_controller7.6.100.0cpe:2.3:h:cisco:wireless_lan_controller:7.6.100.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.001

Percentile

49.1%

Related for CISCO-SA-20150406-CVE-2015-0690