CVE-2014-3428: XSS
Published Jun 16, 2014
·Updated
Cross-site scripting (XSS) vulnerability in Yealink VoIP Phones with firmware 28.72.0.2 allows remote attackers to inject arbitrary web script or HTML via the model parameter to servlet.
Affected Software
4 affected components
Yealink Voip Phone Firmware=28.72.0.2
Yealink VoIP Phone=28.2.0.128.0.0.0
All of the following
Yealink Voip Phone Firmware=28.72.0.2
Yealink VoIP Phone=28.2.0.128.0.0.0
Event History
Jun 16, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3428?
CVE-2014-3428 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2014-3428?
To fix CVE-2014-3428, update the firmware of your Yealink VoIP Phones to a version that addresses this vulnerability.
3
Which versions of Yealink VoIP Phones are affected by CVE-2014-3428?
CVE-2014-3428 affects Yealink VoIP Phones running firmware version 28.72.0.2 and 28.2.0.128.0.0.0.
4
What type of vulnerability is CVE-2014-3428?
CVE-2014-3428 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject scripts.
5
Can CVE-2014-3428 be exploited remotely?
Yes, CVE-2014-3428 can be exploited remotely via the model parameter to the servlet.