CVE-2014-0332: XSS
Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the nodeid parameter in a ScreenDisplayManager genNetwork action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0332?
CVE-2014-0332 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-0332?
To fix CVE-2014-0332, upgrade to SonicWALL GMS and Analyzer version 7.1 SP2 or later.
Which software is affected by CVE-2014-0332?
CVE-2014-0332 affects SonicWALL GMS versions 7.0, 7.1 and SonicWALL Analyzer versions 7.0 and 7.1 prior to SP2.
What type of attack does CVE-2014-0332 facilitate?
CVE-2014-0332 facilitates cross-site scripting (XSS) attacks that can allow remote attackers to inject arbitrary web scripts or HTML.
Is the SonicWALL UMA E5000 vulnerable to CVE-2014-0332?
No, the SonicWALL UMA E5000 is not affected by CVE-2014-0332.