First published: Sat Dec 13 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Security Manager | <=9.2.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3364 is classified as a medium severity vulnerability due to its impact on the security of web applications.
To fix CVE-2014-3364, update Cisco Prime Security Manager to version 9.2.1-3 or a later version.
CVE-2014-3364 can allow remote attackers to perform cross-site scripting attacks, potentially compromising user data.
CVE-2014-3364 affects Cisco Prime Security Manager versions up to and including 9.2.1-2.
There are no official workarounds for CVE-2014-3364, so upgrading to the latest version is recommended.