4.3
CVSSv2

CVE-2015-6402

Published: 14/12/2015 Updated: 13/09/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote malicious users to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter 5.5.10

cisco epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter 5.5.11

cisco epc3928 docsis 3.0 8x4 wireless residential gateway with embedded digital voice adapter 5.7.1

Vendor Advisories

A vulnerability in the web-based management interface of the Cisco EPC3928 Wireless Residential Gateway could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system The vulnerability is due to insufficient input validation of user-supplied value an ...

Exploits

# Title: Cisco EPC 3928 Multiple Vulnerabilities # Vendor: wwwciscocom/ # Vulnerable Version(s): Cisco Model EPC3928 DOCSIS 30 8x4 Wireless Residential Gateway # CVE References: CVE-2015-6401 / CVE-2015-6402 / CVE-2016-1328 / CVE-2016-1336 / CVE-2016-1337 # Author: Patryk Bogdan from Secorda security team (secordacom/) ======== ...
Cisco EPC 3928 suffers from cross site scripting, command execution, denial of service, and other vulnerabilities ...