First published: Fri Apr 04 2014(Updated: )
Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Emergency Responder | <=8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2116 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2014-2116, upgrade Cisco Emergency Responder to version 8.6 or later.
CVE-2014-2116 affects all versions of Cisco Emergency Responder up to and including 8.6.
CVE-2014-2116 allows remote attackers to inject web pages and alter dynamic content.
There are no specifically recommended workarounds for CVE-2014-2116, but the best practice is to upgrade to a fixed version.