CVE-2015-3976: GE Multilink Cross-site Scripting
Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1 and earlier.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3976?
CVE-2015-3976 is classified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-3976?
To mitigate CVE-2015-3976, update to versions of GE Multilink firmware that are later than 5.2.0 for ML810/3000/3100 and later than 4.2.1 for ML800/1200/1600/2400.
What products are affected by CVE-2015-3976?
CVE-2015-3976 affects GE Multilink ML810, ML3000, ML3100 series switches running firmware version 5.2.0 and earlier, as well as ML800, ML1200, ML1600, and ML2400 running version 4.2.1 and earlier.
What type of attack does CVE-2015-3976 facilitate?
CVE-2015-3976 facilitates cross-site scripting (XSS) attacks, allowing attackers to execute arbitrary JavaScript in the context of the victim's browser.
Is there a workaround for CVE-2015-3976?
There are no documented workarounds for CVE-2015-3976; upgrading the firmware is necessary for a permanent fix.