Lucene search

K
cveCiscoCVE-2014-3324
HistoryJul 26, 2014 - 11:11 a.m.

CVE-2014-3324

2014-07-2611:11:57
CWE-79
cisco
web.nvd.nist.gov
28
cve-2014-3324
cross-site scripting
xss
cisco telepresence server software
remote code injection

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

58.7%

Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.

Affected configurations

Nvd
Node
ciscotelepresence_server_softwareMatch3.0\(2.24\)
OR
ciscotelepresence_server_softwareMatch3.1\(1.98\)
OR
ciscotelepresence_server_softwareMatch4.0\(1.57\)
OR
ciscotelepresence_server_softwareMatch4.0\(2.8\)
VendorProductVersionCPE
ciscotelepresence_server_software3.0(2.24)cpe:2.3:a:cisco:telepresence_server_software:3.0\(2.24\):*:*:*:*:*:*:*
ciscotelepresence_server_software3.1(1.98)cpe:2.3:a:cisco:telepresence_server_software:3.1\(1.98\):*:*:*:*:*:*:*
ciscotelepresence_server_software4.0(1.57)cpe:2.3:a:cisco:telepresence_server_software:4.0\(1.57\):*:*:*:*:*:*:*
ciscotelepresence_server_software4.0(2.8)cpe:2.3:a:cisco:telepresence_server_software:4.0\(2.8\):*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.002

Percentile

58.7%

Related for CVE-2014-3324