CVE-2015-0690: XSS
Published Apr 7, 2015
·Updated
Cross-site scripting (XSS) vulnerability in the HTML help system on Cisco Wireless LAN Controller (WLC) devices before 8.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCun95178.
Affected Software
3 affected components
Cisco Wireless LAN Controller Software<=8.0.72.140
Cisco Wireless LAN Controller Software=7.4.121.0
Cisco Wireless LAN Controller Software=7.6.100.0
Event History
Apr 7, 2015
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0690?
CVE-2015-0690 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2015-0690?
To fix CVE-2015-0690, upgrade your Cisco Wireless LAN Controller software to a version above 8.0.72.140 or to 7.4.121.0 or 7.6.100.0.
3
What types of devices are affected by CVE-2015-0690?
CVE-2015-0690 affects Cisco Wireless LAN Controller devices running specific software versions prior to 8.0.
4
Can CVE-2015-0690 be exploited remotely?
Yes, CVE-2015-0690 can be exploited remotely by attackers through crafted URLs.
5
What is the nature of the vulnerability in CVE-2015-0690?
CVE-2015-0690 is a cross-site scripting (XSS) vulnerability that allows injection of arbitrary web scripts or HTML.