Lucene search

K
cveCiscoCVE-2014-2118
HistoryMar 27, 2014 - 9:55 p.m.

CVE-2014-2118

2014-03-2721:55:09
CWE-79
cisco
web.nvd.nist.gov
37
cve
2014
2118
cisco
prime
security manager
xss
vulnerabilities
dashboard
html
documents
prsm
remote attackers
web script
bug id
cscun50687

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

60.1%

Multiple cross-site scripting (XSS) vulnerabilities in dashboard-related HTML documents in Cisco Prime Security Manager (aka PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun50687.

Affected configurations

Nvd
Node
ciscoprime_security_managerRange≀9.2.1-2
OR
ciscoprime_security_managerMatch9.0
OR
ciscoprime_security_managerMatch9.1
OR
ciscoprime_security_managerMatch9.1.2-29
OR
ciscoprime_security_managerMatch9.1.2-42
OR
ciscoprime_security_managerMatch9.1.3-8
OR
ciscoprime_security_managerMatch9.1.3-10
OR
ciscoprime_security_managerMatch9.1.3-13
OR
ciscoprime_security_managerMatch9.2
OR
ciscoprime_security_managerMatch9.2.1-1
VendorProductVersionCPE
ciscoprime_security_manager*cpe:2.3:a:cisco:prime_security_manager:*:*:*:*:*:*:*:*
ciscoprime_security_manager9.0cpe:2.3:a:cisco:prime_security_manager:9.0:*:*:*:*:*:*:*
ciscoprime_security_manager9.1cpe:2.3:a:cisco:prime_security_manager:9.1:*:*:*:*:*:*:*
ciscoprime_security_manager9.1.2-29cpe:2.3:a:cisco:prime_security_manager:9.1.2-29:*:*:*:*:*:*:*
ciscoprime_security_manager9.1.2-42cpe:2.3:a:cisco:prime_security_manager:9.1.2-42:*:*:*:*:*:*:*
ciscoprime_security_manager9.1.3-8cpe:2.3:a:cisco:prime_security_manager:9.1.3-8:*:*:*:*:*:*:*
ciscoprime_security_manager9.1.3-10cpe:2.3:a:cisco:prime_security_manager:9.1.3-10:*:*:*:*:*:*:*
ciscoprime_security_manager9.1.3-13cpe:2.3:a:cisco:prime_security_manager:9.1.3-13:*:*:*:*:*:*:*
ciscoprime_security_manager9.2cpe:2.3:a:cisco:prime_security_manager:9.2:*:*:*:*:*:*:*
ciscoprime_security_manager9.2.1-1cpe:2.3:a:cisco:prime_security_manager:9.2.1-1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

60.1%