First published: Tue Dec 10 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Scientific Atlanta DPC/EPD 3208 | ||
Cisco Scientific Atlanta DPC/EPC2100 | ||
Cisco Scientific Atlanta DPC/EPC2202 | ||
Cisco Scientific Atlanta DPC/EPC2203 | ||
Cisco Scientific Atlanta DPC/EPC2325 | ||
Cisco Scientific Atlanta DPC/EPC2425 | ||
Cisco Scientific Atlanta DPC/EPC2434 | ||
Cisco Scientific Atlanta DPC/EPC2505 | ||
Cisco Scientific Atlanta DPC/EPC3010 | ||
Cisco Scientific Atlanta DPC/EPC3212 | ||
Cisco Scientific Atlanta EPC2420 | ||
Cisco Scientific Atlanta DPC3000/EPC3000 | ||
Cisco Scientific Atlanta DPC3008/EPC3008 | ||
Cisco DPC3825 | ||
Cisco DPC3925 | ||
Cisco Scientific Atlanta Dpq/epq2160 | ||
Cisco Scientific Atlanta Dpq2202 | ||
Cisco Scientific Atlanta Dpq2425 | ||
Cisco Scientific Atlanta Dpq3212 | ||
Cisco Dpq3925 | ||
Cisco Scientific Atlanta DPR362 | ||
Cisco Scientific Atlanta DPW700 | ||
Cisco Scientific Atlanta Dpw730 | ||
Cisco Scientific Atlanta Dpw939 | ||
Cisco Scientific Atlanta DPW941 | ||
Cisco Scientific Atlanta DPX/EPX2100 | ||
Cisco Scientific Atlanta Dpx/epx2203 | ||
Cisco Scientific Atlanta Dpx/epx2203c | ||
Cisco Scientific Atlanta Dpx100/120 | ||
Cisco Scientific Atlanta Dpx110 | ||
Cisco Scientific Atlanta Dpx130 | ||
Cisco Scientific Atlanta Dpx213 | ||
Cisco Scientific Atlanta DPX2213 | ||
Cisco Scientific Atlanta EPC2420 | ||
Cisco Scientific Atlanta EPC3825 | ||
Cisco Scientific Atlanta DPC3925 | ||
Cisco Scientific Atlanta Wag310g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-3047 is considered medium due to its potential for exploitation via cross-site scripting.
To fix CVE-2012-3047, users should upgrade their Cisco Scientific Atlanta cable modems to the latest firmware version provided by Cisco.
CVE-2012-3047 affects multiple Cisco Scientific Atlanta cable modem models including DPC/EPD 3208, EPC2100, EPC2202, EPC2203, and more.
Yes, CVE-2012-3047 can be exploited remotely, allowing attackers to inject malicious web scripts.
CVE-2012-3047 is categorized as a cross-site scripting (XSS) vulnerability, enabling attackers to perform script injection.