CVE-2014-3809: XSS
Published Jan 31, 2020
·Updated
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.
Affected Software
6 affected components
Nokia 1830 Photonic Service Switch-4 Firmware<=6.0
Nokia 1830 Photonic Service Switch-4
Nokia 1830 Photonic Service Switch-16 Firmware<=6.0
Nokia 1830 Photonic Service Switch-16
Nokia 1830 Photonic Service Switch-32 Firmware<=6.0
Nokia 1830 Photonic Service Switch-32
Event History
Jan 31, 2020
CVE Published
via MITRE·09:55 PM
Data Sourced
via MITRE·09:55 PM
Description
Frequently Asked Questions
1
What is CVE-2014-3809?
CVE-2014-3809 is a cross-site scripting (XSS) vulnerability in the management interface of Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier.
2
How does CVE-2014-3809 affect the affected software?
CVE-2014-3809 affects Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier versions.
3
How severe is CVE-2014-3809?
CVE-2014-3809 has a severity rating of 6.1 (medium).
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2014-3809?
The CWE ID for CVE-2014-3809 is CWE-79.
5
How can I fix the CVE-2014-3809 vulnerability?
To fix the CVE-2014-3809 vulnerability, update the Alcatel-Lucent 1830 Photonic Service Switch (PSS) to version 6.1 or later.