CVE-2014-5417: Meinberg Radio Clocks LANTIME M-Series
Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5417?
CVE-2014-5417 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2014-5417?
To fix CVE-2014-5417, upgrade the Meinberg NTP Server firmware to a version later than 6.15.019.
Which devices are affected by CVE-2014-5417?
CVE-2014-5417 affects Meinberg LANTIME M-Series devices running firmware version 6.15.019 and earlier.
What type of vulnerability is CVE-2014-5417?
CVE-2014-5417 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Are there any mitigations for CVE-2014-5417?
The best mitigation for CVE-2014-5417 is to ensure that the firmware is updated to a safe version and to restrict access to the management interface.