ID

VAR-201401-0343


CVE

CVE-2014-0680


TITLE

Cisco Identity Services Engine of NAC Web Agent Component cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-001279

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCui15038. The platform monitors the network by collecting real-time information on the network, users and devices, and formulating and implementing corresponding policies

Trust: 1.98

sources: NVD: CVE-2014-0680 // JVNDB: JVNDB-2014-001279 // BID: 65227 // VULHUB: VHN-68173

AFFECTED PRODUCTS

vendor:ciscomodel:identity services enginescope:eqversion: -

Trust: 1.6

vendor:ciscomodel:identity services enginescope: - version: -

Trust: 0.8

vendor:ciscomodel:identity services engine softwarescope:lteversion:1.2(.1 patch 2)

Trust: 0.8

sources: JVNDB: JVNDB-2014-001279 // CNNVD: CNNVD-201401-582 // NVD: CVE-2014-0680

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-0680
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-0680
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201401-582
value: MEDIUM

Trust: 0.6

VULHUB: VHN-68173
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-0680
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-68173
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-68173 // JVNDB: JVNDB-2014-001279 // CNNVD: CNNVD-201401-582 // NVD: CVE-2014-0680

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-68173 // JVNDB: JVNDB-2014-001279 // NVD: CVE-2014-0680

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201401-582

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201401-582

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-001279

PATCH

title:Cisco Identity Services Engine HTTP Control Interface for NAC Web Agent Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0680

Trust: 0.8

title:32617url:http://tools.cisco.com/security/center/viewAlert.x?alertId=32617

Trust: 0.8

sources: JVNDB: JVNDB-2014-001279

EXTERNAL IDS

db:NVDid:CVE-2014-0680

Trust: 2.8

db:BIDid:65227

Trust: 1.4

db:OSVDBid:102588

Trust: 1.1

db:SECUNIAid:56672

Trust: 1.1

db:SECTRACKid:1029701

Trust: 1.1

db:JVNDBid:JVNDB-2014-001279

Trust: 0.8

db:CNNVDid:CNNVD-201401-582

Trust: 0.7

db:CISCOid:20140128 CISCO IDENTITY SERVICES ENGINE HTTP CONTROL INTERFACE FOR NAC WEB AGENT CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-68173

Trust: 0.1

sources: VULHUB: VHN-68173 // BID: 65227 // JVNDB: JVNDB-2014-001279 // CNNVD: CNNVD-201401-582 // NVD: CVE-2014-0680

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-0680

Trust: 1.7

url:http://www.securityfocus.com/bid/65227

Trust: 1.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=32617

Trust: 1.1

url:http://osvdb.org/102588

Trust: 1.1

url:http://www.securitytracker.com/id/1029701

Trust: 1.1

url:http://secunia.com/advisories/56672

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-0680

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-0680

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-68173 // BID: 65227 // JVNDB: JVNDB-2014-001279 // CNNVD: CNNVD-201401-582 // NVD: CVE-2014-0680

CREDITS

Cisco

Trust: 0.3

sources: BID: 65227

SOURCES

db:VULHUBid:VHN-68173
db:BIDid:65227
db:JVNDBid:JVNDB-2014-001279
db:CNNVDid:CNNVD-201401-582
db:NVDid:CVE-2014-0680

LAST UPDATE DATE

2024-11-23T22:46:08.427000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-68173date:2018-01-03T00:00:00
db:BIDid:65227date:2014-01-31T01:55:00
db:JVNDBid:JVNDB-2014-001279date:2014-01-30T00:00:00
db:CNNVDid:CNNVD-201401-582date:2014-03-07T00:00:00
db:NVDid:CVE-2014-0680date:2024-11-21T02:02:38.933

SOURCES RELEASE DATE

db:VULHUBid:VHN-68173date:2014-01-29T00:00:00
db:BIDid:65227date:2014-01-28T00:00:00
db:JVNDBid:JVNDB-2014-001279date:2014-01-30T00:00:00
db:CNNVDid:CNNVD-201401-582date:2014-01-29T00:00:00
db:NVDid:CVE-2014-0680date:2014-01-29T18:34:05.310