ID

VAR-201401-0332


CVE

CVE-2014-0668


TITLE

Cisco Secure Access Control System Portal cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-001213

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCue65949. Cisco Secure ACS is a central management platform for Cisco network devices that controls device authentication and authorization. Because the program fails to properly filter user input, a remote attacker is allowed to exploit the vulnerability to execute arbitrary script code in the browser of a trusted user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCue65949. The system can respectively control network access and network device access through RADIUS and TACACS protocols

Trust: 2.52

sources: NVD: CVE-2014-0668 // JVNDB: JVNDB-2014-001213 // CNVD: CNVD-2014-00490 // BID: 65016 // VULHUB: VHN-68161

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-00490

AFFECTED PRODUCTS

vendor:ciscomodel:secure access control systemscope:eqversion: -

Trust: 1.6

vendor:ciscomodel:secure access control system softwarescope:lteversion:5.4.0.46.3

Trust: 0.8

vendor:ciscomodel:secure acsscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2014-00490 // JVNDB: JVNDB-2014-001213 // CNNVD: CNNVD-201401-384 // NVD: CVE-2014-0668

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0668
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-0668
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-00490
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201401-384
value: MEDIUM

Trust: 0.6

VULHUB: VHN-68161
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-0668
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-00490
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-68161
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-00490 // VULHUB: VHN-68161 // JVNDB: JVNDB-2014-001213 // CNNVD: CNNVD-201401-384 // NVD: CVE-2014-0668

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-68161 // JVNDB: JVNDB-2014-001213 // NVD: CVE-2014-0668

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-384

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201401-384

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001213

PATCH

title:Cisco Secure ACS Portal Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0668

Trust: 0.8

title:32489url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32489

Trust: 0.8

title:Patch for Cisco Secure ACS Interface Cross-Site Scripting Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/42798

Trust: 0.6

sources: CNVD: CNVD-2014-00490 // JVNDB: JVNDB-2014-001213

EXTERNAL IDS

db:NVDid:CVE-2014-0668

Trust: 3.4

db:BIDid:65016

Trust: 2.0

db:SECUNIAid:56543

Trust: 1.1

db:SECTRACKid:1029654

Trust: 1.1

db:OSVDBid:102256

Trust: 1.1

db:JVNDBid:JVNDB-2014-001213

Trust: 0.8

db:CNNVDid:CNNVD-201401-384

Trust: 0.7

db:CNVDid:CNVD-2014-00490

Trust: 0.6

db:CISCOid:20140117 CISCO SECURE ACS PORTAL CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68161

Trust: 0.1

sources: CNVD: CNVD-2014-00490 // VULHUB: VHN-68161 // BID: 65016 // JVNDB: JVNDB-2014-001213 // CNNVD: CNNVD-201401-384 // NVD: CVE-2014-0668

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0668

Trust: 2.3

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0668

Trust: 1.4

url:http://www.securityfocus.com/bid/65016

Trust: 1.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=32489

Trust: 1.1

url:http://osvdb.org/102256

Trust: 1.1

url:http://www.securitytracker.com/id/1029654

Trust: 1.1

url:http://secunia.com/advisories/56543

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/90561

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0668

Trust: 0.8

url:www.cisco.com

Trust: 0.3

sources: CNVD: CNVD-2014-00490 // VULHUB: VHN-68161 // BID: 65016 // JVNDB: JVNDB-2014-001213 // CNNVD: CNNVD-201401-384 // NVD: CVE-2014-0668

CREDITS

Cisco

Trust: 0.3

sources: BID: 65016

SOURCES

db:CNVDid:CNVD-2014-00490
db:VULHUBid:VHN-68161
db:BIDid:65016
db:JVNDBid:JVNDB-2014-001213
db:CNNVDid:CNNVD-201401-384
db:NVDid:CVE-2014-0668

LAST UPDATE DATE

2024-11-23T22:56:39+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-00490date:2014-01-22T00:00:00
db:VULHUBid:VHN-68161date:2017-08-29T00:00:00
db:BIDid:65016date:2014-01-22T00:22:00
db:JVNDBid:JVNDB-2014-001213date:2014-01-22T00:00:00
db:CNNVDid:CNNVD-201401-384date:2014-01-26T00:00:00
db:NVDid:CVE-2014-0668date:2024-11-21T02:02:37.557

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-00490date:2014-01-22T00:00:00
db:VULHUBid:VHN-68161date:2014-01-20T00:00:00
db:BIDid:65016date:2014-01-17T00:00:00
db:JVNDBid:JVNDB-2014-001213date:2014-01-22T00:00:00
db:CNNVDid:CNNVD-201401-384date:2014-01-26T00:00:00
db:NVDid:CVE-2014-0668date:2014-01-20T04:58:49.807