Lucene search

K
cveIbmCVE-2013-5442
HistoryNov 13, 2013 - 3:55 p.m.

CVE-2013-5442

2013-11-1315:55:03
CWE-79
ibm
web.nvd.nist.gov
25
cve-2013-5442
cross-site scripting
xss
ibm security network protection
lmi
firmware 5.1

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

55.1%

Cross-site scripting (XSS) vulnerability in the Local Management Interface (LMI) in IBM Security Network Protection on XGS 5100 devices with firmware 5.1 before 5.1.0.6 and 5.1.1 before 5.1.1.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected configurations

Nvd
Node
ibmsecurity_network_protection_firmwareMatch5.1
OR
ibmsecurity_network_protection_firmwareMatch5.1.1
AND
ibmsecurity_network_protection_xgs_5100Match-
VendorProductVersionCPE
ibmsecurity_network_protection_firmware5.1cpe:2.3:o:ibm:security_network_protection_firmware:5.1:*:*:*:*:*:*:*
ibmsecurity_network_protection_firmware5.1.1cpe:2.3:o:ibm:security_network_protection_firmware:5.1.1:*:*:*:*:*:*:*
ibmsecurity_network_protection_xgs_5100-cpe:2.3:h:ibm:security_network_protection_xgs_5100:-:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

7.1

Confidence

Low

EPSS

0.002

Percentile

55.1%

Related for CVE-2013-5442