CVE-2014-3324: XSS
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3324?
CVE-2014-3324 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2014-3324?
To fix CVE-2014-3324, update the Cisco TelePresence Server Software to the latest version that addresses the identified vulnerabilities.
What are the affected versions for CVE-2014-3324?
The affected versions for CVE-2014-3324 include Cisco TelePresence Server Software versions 3.0(2.24), 3.1(1.98), and 4.0(1.57) and 4.0(2.8).
What kind of attacks can CVE-2014-3324 enable?
CVE-2014-3324 can enable remote attackers to perform cross-site scripting (XSS) attacks through the login page of the administrative web interface.
Is there a workaround for CVE-2014-3324?
There is no specific workaround for CVE-2014-3324; upgrading to a patched version is the recommended mitigation.