Lucene search

K
cveCiscoCVE-2015-6400
HistoryDec 13, 2015 - 3:59 a.m.

CVE-2015-6400

2015-12-1303:59:02
CWE-79
cisco
web.nvd.nist.gov
36
cve-2015-6400
cisco emergency responder
xss
injection
bug id cscuv25547
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

49.1%

Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547.

Affected configurations

Nvd
Node
ciscoemergency_responderMatch10.5\(1a\)
VendorProductVersionCPE
ciscoemergency_responder10.5(1a)cpe:2.3:a:cisco:emergency_responder:10.5\(1a\):*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

49.1%

Related for CVE-2015-6400