First published: Thu Feb 12 2015(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Prime Security Manager (PRSM) 9.2(.1-2) and earlier allow remote attackers to inject arbitrary web script or HTML via crafted input to the (1) Dashboard or (2) Configure Realm page, aka Bug ID CSCuo94808.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Prime Security Manager | <=9.2.1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3365 has been classified as a medium severity vulnerability due to the potential for cross-site scripting attacks.
To mitigate CVE-2014-3365, upgrade to a version of Cisco Prime Security Manager later than 9.2.1-2.
CVE-2014-3365 allows remote attackers to execute arbitrary web scripts or HTML through cross-site scripting.
CVE-2014-3365 affects Cisco Prime Security Manager versions up to and including 9.2.1-2.
Yes, CVE-2014-3365 can be exploited by unauthenticated attackers through crafted input.