Overview
Cisco AsyncOS contains a reflected cross-site scripting (XSS) vulnerability.
Description
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') - CVE-2014-3289 Cisco AsyncOS, the underlying OS for the Cisco Email Security Appliance, Web Security Appliance, and Content Security Management Appliance, contains a reflected cross-site scripting vulnerability in the reports overview page of the management interface. An attacker is able to load arbitrary script in the context of the user's browser through thedate_range parameter. |
Impact
A remote unauthenticated attacker may be able to execute arbitrary script in the context of the end-user's browser session. |
Solution
Apply an Update |
Restrict Access |
Vendor Information (Learn More)
Vendor | Status | Date Notified | Date Updated |
---|---|---|---|
Cisco Systems, Inc. | Affected | 17 Feb 2014 | 10 Jun 2014 |
If you are a vendor and your product is affected, let us know.
CVSS Metrics (Learn More)
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Temporal | 3.6 | E:F/RL:OF/RC:C |
Environmental | 2.7 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://www.cisco.com/c/en/us/products/security/email-security-appliance/asyncos_index.html
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3289
- http://cwe.mitre.org/data/definitions/79.html
Credit
Thanks to William Costa for reporting this vulnerability.
This document was written by Chris King.
Other Information
- CVE IDs: CVE-2014-3289
- Date Public: 09 6월 2014
- Date First Published: 10 6월 2014
- Date Last Updated: 10 6월 2014
- Document Revision: 15
'취약점 정보1' 카테고리의 다른 글
Snake In The Grass: Python-based Malware Used For Targeted Attacks (0) | 2014.06.17 |
---|---|
How I discovered CCS Injection Vulnerability (CVE-2014-0224) (0) | 2014.06.11 |
Unauthorized modification of UEFI variables in UEFI systems (0) | 2014.06.11 |
Adobe Flash Player 업데이트 권고 (0) | 2014.06.11 |
SSL/TLS MITM vulnerability (CVE-2014-0224) (0) | 2014.06.06 |