4.3
CVSSv2

CVE-2014-3809

Published: 31/01/2020 Updated: 05/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nokia 1830_photonic_service_switch-4_firmware

nokia 1830_photonic_service_switch-16_firmware

nokia 1830_photonic_service_switch-32_firmware

Exploits

Swisscom CSIRT discovered a security flaw in the management interface of the Alcatel Lucent 1830 Photonic Service Switch series that allows for cross site scripting attacks Versions 60 and below are affected ...