| Vulnerability Name: | CVE-2014-3289 (CCN-93704) | ||||||||
| Assigned: | 2014-06-10 | ||||||||
| Published: | 2014-06-10 | ||||||||
| Updated: | 2018-10-30 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, as demonstrated by the date_range parameter to monitor/reports/overview on the IronPort ESA, aka Bug IDs CSCun07998, CSCun07844, and CSCun07888. | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-79 | ||||||||
| Vulnerability Consequences: | Cross-Site Scripting | ||||||||
| References: | Source: MITRE Type: CNA CVE-2014-3289 Source: MISC Type: UNKNOWN http://packetstormsecurity.com/files/127004/Cisco-Ironport-Email-Security-Virtual-Appliance-8.0.0-671-XSS.html Source: FULLDISC Type: Exploit, Third Party Advisory, VDB Entry 20140609 Cisco AsyncOS Cross-Site Scripting Vulnerability CVE-2014-3289 Source: SECUNIA Type: Permissions Required 58296 Source: CCN Type: Cisco Security Notice Cisco AsyncOS Cross-Site Scripting Vulnerability Source: CISCO Type: Vendor Advisory 20140609 Cisco AsyncOS Cross-Site Scripting Vulnerability Source: CONFIRM Type: Vendor Advisory http://tools.cisco.com/security/center/viewAlert.x?alertId=34569 Source: CCN Type: US-CERT VU#613308 Cisco AsyncOS contains a reflected cross-site scripting (XSS) vulnerability Source: CERT-VN Type: UNKNOWN VU#613308 Source: BID Type: Third Party Advisory, VDB Entry 67943 Source: CCN Type: BID-67943 Cisco AsyncOS Software CVE-2014-3289 Cross Site Scripting Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1030407 Source: XF Type: UNKNOWN cisco-asyncos-cve20143289-xss(93704) Source: CCN Type: Packet Storm Security [06-09-2014] Cisco Ironport Email Security Virtual Appliance 8.0.0-671 XSS | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||