First published: Sat Jul 26 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the login page in the administrative web interface in Cisco TelePresence Server Software 4.0(2.8) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCup90060.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco TelePresence Server | =3.0\(2.24\) | |
Cisco TelePresence Server | =3.1\(1.98\) | |
Cisco TelePresence Server | =4.0\(1.57\) | |
Cisco TelePresence Server | =4.0\(2.8\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3324 is considered a high severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2014-3324, update the Cisco TelePresence Server Software to the latest version that addresses the identified vulnerabilities.
The affected versions for CVE-2014-3324 include Cisco TelePresence Server Software versions 3.0(2.24), 3.1(1.98), and 4.0(1.57) and 4.0(2.8).
CVE-2014-3324 can enable remote attackers to perform cross-site scripting (XSS) attacks through the login page of the administrative web interface.
There is no specific workaround for CVE-2014-3324; upgrading to a patched version is the recommended mitigation.