First published: Thu Mar 27 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in dashboard-related HTML documents in Cisco Prime Security Manager (aka PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCun50687.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Security Manager | <=9.2.1-2 | |
Cisco Prime Security Manager | =9.0 | |
Cisco Prime Security Manager | =9.1 | |
Cisco Prime Security Manager | =9.1.2-29 | |
Cisco Prime Security Manager | =9.1.2-42 | |
Cisco Prime Security Manager | =9.1.3-8 | |
Cisco Prime Security Manager | =9.1.3-10 | |
Cisco Prime Security Manager | =9.1.3-13 | |
Cisco Prime Security Manager | =9.2 | |
Cisco Prime Security Manager | =9.2.1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2118 is classified as high due to the potential for remote code execution via XSS.
To fix CVE-2014-2118, upgrade to a patched version of Cisco Prime Security Manager that addresses these vulnerabilities.
CVE-2014-2118 may allow attackers to execute arbitrary web scripts or HTML, leading to data theft or session hijacking.
CVE-2014-2118 affects Cisco Prime Security Manager versions 9.0 through 9.2.1-2 and earlier.
Yes, CVE-2014-2118 can be exploited by remote attackers without requiring user interaction.