6.1
CVSSv3

CVE-2016-6359

Published: 22/08/2016 Updated: 28/11/2016
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote malicious users to inject arbitrary web script or HTML via a crafted value, aka Bug IDs CSCva40650 and CSCva40817.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco transport gateway installation software 4.1\\(4.0\\)

Vendor Advisories

A vulnerability in the web framework of the Cisco Smart Call Home Transport Gateway could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack The vulnerability is due to insufficient input validation of a user-supplied value An attacker could exploit this vulnerability by persuading a user of an affected syst ...