ID

VAR-201502-0335


CVE

CVE-2014-2147


TITLE

Cisco Prime Infrastructure of Web Vulnerabilities that could cause clickjacking attacks in the interface

Trust: 0.8

sources: JVNDB: JVNDB-2014-007884

DESCRIPTION

The web interface in Cisco Prime Infrastructure 2.1 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuj42444. This case " Cross frame scripting (XFS)" Vulnerability related to the problem. Cisco Prime Infrastructure is prone to a cross-frame scripting vulnerability. Successful exploits will allow attackers to bypass the same-origin policy and perform unauthorized actions; other attacks are possible. This issue is being tracked by Cisco Bug ID CSCuj42444. There is a security vulnerability in the web interface of Cisco PI 2.1 and earlier versions. The vulnerability is caused by the program not properly restricting the use of IFRAME elements

Trust: 1.98

sources: NVD: CVE-2014-2147 // JVNDB: JVNDB-2014-007884 // BID: 72551 // VULHUB: VHN-70086

AFFECTED PRODUCTS

vendor:ciscomodel:prime infrastructurescope:lteversion:2.1

Trust: 1.8

vendor:ciscomodel:prime infrastructurescope:eqversion:2.1

Trust: 0.6

sources: JVNDB: JVNDB-2014-007884 // CNNVD: CNNVD-201502-261 // NVD: CVE-2014-2147

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2147
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2147
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201502-261
value: MEDIUM

Trust: 0.6

VULHUB: VHN-70086
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-2147
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-70086
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-70086 // JVNDB: JVNDB-2014-007884 // CNNVD: CNNVD-201502-261 // NVD: CVE-2014-2147

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.9

sources: VULHUB: VHN-70086 // JVNDB: JVNDB-2014-007884 // NVD: CVE-2014-2147

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201502-261

TYPE

input validation

Trust: 0.6

sources: CNNVD: CNNVD-201502-261

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-007884

PATCH

title:Cisco Prime Infrastructure Cross-Frame Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2147

Trust: 0.8

title:37419url:http://tools.cisco.com/security/center/viewAlert.x?alertId=37419

Trust: 0.8

sources: JVNDB: JVNDB-2014-007884

EXTERNAL IDS

db:NVDid:CVE-2014-2147

Trust: 2.8

db:BIDid:72551

Trust: 1.4

db:SECTRACKid:1031715

Trust: 1.1

db:JVNDBid:JVNDB-2014-007884

Trust: 0.8

db:CNNVDid:CNNVD-201502-261

Trust: 0.7

db:VULHUBid:VHN-70086

Trust: 0.1

sources: VULHUB: VHN-70086 // BID: 72551 // JVNDB: JVNDB-2014-007884 // CNNVD: CNNVD-201502-261 // NVD: CVE-2014-2147

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-2147

Trust: 1.7

url:http://tools.cisco.com/security/center/viewalert.x?alertid=37419

Trust: 1.7

url:http://www.securityfocus.com/bid/72551

Trust: 1.1

url:http://www.securitytracker.com/id/1031715

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/100755

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2147

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2147

Trust: 0.8

url:www.cisco.com

Trust: 0.3

sources: VULHUB: VHN-70086 // BID: 72551 // JVNDB: JVNDB-2014-007884 // CNNVD: CNNVD-201502-261 // NVD: CVE-2014-2147

CREDITS

Cisco

Trust: 0.3

sources: BID: 72551

SOURCES

db:VULHUBid:VHN-70086
db:BIDid:72551
db:JVNDBid:JVNDB-2014-007884
db:CNNVDid:CNNVD-201502-261
db:NVDid:CVE-2014-2147

LAST UPDATE DATE

2024-11-23T21:55:06.027000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-70086date:2017-08-29T00:00:00
db:BIDid:72551date:2015-02-16T00:04:00
db:JVNDBid:JVNDB-2014-007884date:2015-02-17T00:00:00
db:CNNVDid:CNNVD-201502-261date:2015-02-12T00:00:00
db:NVDid:CVE-2014-2147date:2024-11-21T02:05:44.570

SOURCES RELEASE DATE

db:VULHUBid:VHN-70086date:2015-02-12T00:00:00
db:BIDid:72551date:2015-02-09T00:00:00
db:JVNDBid:JVNDB-2014-007884date:2015-02-17T00:00:00
db:CNNVDid:CNNVD-201502-261date:2015-02-12T00:00:00
db:NVDid:CVE-2014-2147date:2015-02-12T01:59:00.063