4.3
CVSSv2

CVE-2014-3329

Published: 29/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the web-server component in Cisco Prime Data Center Network Manager (DCNM) 6.3(2) and previous versions allows remote malicious users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum86620.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco prime data center network manager 6.2\\(3\\)

cisco prime data center network manager 6.2\\(1\\)

cisco prime data center network manager 6.2\\(5a\\)

cisco prime data center network manager 6.2\\(5\\)

cisco prime data center network manager 6.3\\(1\\)

cisco prime data center network manager

cisco prime data center network manager 6.1\\(1\\)

cisco prime data center network manager 6.1

Vendor Advisories

A vulnerability in the web server hosting the Cisco Prime Data Center Network Manager could allow an unauthenticated, remote attacker to perform a cross-site scripting (XSS) attack against the user of the web interface The issue is due to insufficient input validation of parameters by the web server An attacker could exploit this issue by convin ...