ID

VAR-201407-0391


CVE

CVE-2014-3329


TITLE

Cisco Prime Data Center Network Manager of Web Server component cross-site scripting vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2014-003636

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the web-server component in Cisco Prime Data Center Network Manager (DCNM) 6.3(2) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum86620. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCum86620. The manager provides multi-protocol management of the network and provides troubleshooting capabilities for switch health and performance

Trust: 1.98

sources: NVD: CVE-2014-3329 // JVNDB: JVNDB-2014-003636 // BID: 68926 // VULHUB: VHN-71269

AFFECTED PRODUCTS

vendor:ciscomodel:prime data center network managerscope:eqversion:6.2\(1\)

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:eqversion:6.2\(3\)

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:eqversion:6.3\(1\)

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:eqversion:6.2\(5\)

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:eqversion:6.1\(1\)

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:eqversion:6.2\(5a\)

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:eqversion:6.1

Trust: 1.6

vendor:ciscomodel:prime data center network managerscope:lteversion:6.3\(2\)

Trust: 1.0

vendor:ciscomodel:prime data center network managerscope:lteversion:6.3(2)

Trust: 0.8

vendor:ciscomodel:prime data center network managerscope:eqversion:6.3\(2\)

Trust: 0.6

sources: JVNDB: JVNDB-2014-003636 // CNNVD: CNNVD-201407-706 // NVD: CVE-2014-3329

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3329
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3329
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201407-706
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71269
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3329
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-71269
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-71269 // JVNDB: JVNDB-2014-003636 // CNNVD: CNNVD-201407-706 // NVD: CVE-2014-3329

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-71269 // JVNDB: JVNDB-2014-003636 // NVD: CVE-2014-3329

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201407-706

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201407-706

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003636

PATCH

title:Cisco Prime Data Center Network Manager Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3329

Trust: 0.8

title:35065url:http://tools.cisco.com/security/center/viewAlert.x?alertId=35065

Trust: 0.8

sources: JVNDB: JVNDB-2014-003636

EXTERNAL IDS

db:NVDid:CVE-2014-3329

Trust: 2.8

db:BIDid:68926

Trust: 1.4

db:SECTRACKid:1030652

Trust: 1.1

db:JVNDBid:JVNDB-2014-003636

Trust: 0.8

db:CNNVDid:CNNVD-201407-706

Trust: 0.7

db:VULHUBid:VHN-71269

Trust: 0.1

sources: VULHUB: VHN-71269 // BID: 68926 // JVNDB: JVNDB-2014-003636 // CNNVD: CNNVD-201407-706 // NVD: CVE-2014-3329

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3329

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=35065

Trust: 1.7

url:http://www.securityfocus.com/bid/68926

Trust: 1.1

url:http://www.securitytracker.com/id/1030652

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/94889

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3329

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3329

Trust: 0.8

url:www.cisco.com

Trust: 0.3

sources: VULHUB: VHN-71269 // BID: 68926 // JVNDB: JVNDB-2014-003636 // CNNVD: CNNVD-201407-706 // NVD: CVE-2014-3329

CREDITS

Cisco

Trust: 0.3

sources: BID: 68926

SOURCES

db:VULHUBid:VHN-71269
db:BIDid:68926
db:JVNDBid:JVNDB-2014-003636
db:CNNVDid:CNNVD-201407-706
db:NVDid:CVE-2014-3329

LAST UPDATE DATE

2024-11-23T22:59:40.098000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-71269date:2017-08-29T00:00:00
db:BIDid:68926date:2014-08-01T00:29:00
db:JVNDBid:JVNDB-2014-003636date:2014-07-31T00:00:00
db:CNNVDid:CNNVD-201407-706date:2014-07-30T00:00:00
db:NVDid:CVE-2014-3329date:2024-11-21T02:07:52.703

SOURCES RELEASE DATE

db:VULHUBid:VHN-71269date:2014-07-29T00:00:00
db:BIDid:68926date:2014-07-28T00:00:00
db:JVNDBid:JVNDB-2014-003636date:2014-07-31T00:00:00
db:CNNVDid:CNNVD-201407-706date:2014-07-30T00:00:00
db:NVDid:CVE-2014-3329date:2014-07-29T20:55:08.520