First published: Thu Jul 26 2018(Updated: )
Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
NEC Platforms Calsos CSDX Firmware | <=1.37210411 | |
Necplatforms Calsos Csdx Firmware | ||
Necplatforms Calsos Csdx(p) Firmware | <=4.37210411 | |
Necplatforms Calsos Csdx | ||
Necplatforms Calsos Csdx(s) Firmware | <=2.37210411 | |
Necplatforms Calsos Csdx | ||
Necplatforms Calsos Csdx(d) Firmware | <=3.37210411 | |
Necplatforms Calsos Csdx | ||
Necplatforms Calsos Csdj-b | <=01.03.00 | |
Necplatforms Calsos Csdj-b Firmware | ||
Necplatforms Calsos Csdj-d | <=01.03.00 | |
Necplatforms Calsos Csdj-d Firmware | ||
Nec Csdj-h Firmware | <=01.03.00 | |
Necplatforms Calsos Csdj-h Firmware | ||
Necplatforms Calsos Csdj-a | <=03.00.00 | |
Necplatforms Calsos Csdj-a Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-0614 has a high severity rating due to its potential for cross-site scripting attacks.
To mitigate CVE-2018-0614, update the affected NEC Platforms Calsos firmware to the latest version which patches the vulnerability.
CVE-2018-0614 affects NEC Platforms Calsos CSDX and CSDJ series products with specified firmware versions prior to the recommended updates.
CVE-2018-0614 is classified as a cross-site scripting (XSS) vulnerability.
Yes, CVE-2018-0614 can potentially be exploited remotely due to the nature of cross-site scripting.