ID

VAR-201405-0360


CVE

CVE-2014-3265


TITLE

Cisco Security Manager of Auto Update Server of Web Cross-site scripting vulnerability in the framework

Trust: 0.8

sources: JVNDB: JVNDB-2014-002551

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the Auto Update Server (AUS) web framework in Cisco Security Manager 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuo06900. Cisco Security Device Manager, Cisco Security Device Management Tool, referred to as SDM. It is a graphical router management tool provided by Cisco. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. This issue is being tracked by Cisco Bug ID CSCuo06900. Security Manager 4.2 and prior are vulnerable. The vulnerability is caused by the program's insufficient validation parameters

Trust: 2.52

sources: NVD: CVE-2014-3265 // JVNDB: JVNDB-2014-002551 // CNVD: CNVD-2014-03192 // BID: 67499 // VULHUB: VHN-71205

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-03192

AFFECTED PRODUCTS

vendor:ciscomodel:security managerscope:eqversion:4.2

Trust: 1.6

vendor:ciscomodel:security managerscope:lteversion:4.2

Trust: 0.8

vendor:ciscomodel:security managerscope:lteversion:<=4.2

Trust: 0.6

vendor:ciscomodel:security manager basescope:eqversion:4.2

Trust: 0.3

vendor:ciscomodel:security manager basescope:eqversion:4.1

Trust: 0.3

vendor:ciscomodel:security manager basescope:eqversion:4.0

Trust: 0.3

vendor:ciscomodel:security manager sp2scope:eqversion:4.0.1

Trust: 0.3

vendor:ciscomodel:security manager sp1scope:eqversion:4.0.1

Trust: 0.3

vendor:ciscomodel:security managerscope:eqversion:4.0.1

Trust: 0.3

vendor:ciscomodel:security manager sp1scope:eqversion:4.0

Trust: 0.3

sources: CNVD: CNVD-2014-03192 // BID: 67499 // JVNDB: JVNDB-2014-002551 // CNNVD: CNNVD-201405-385 // NVD: CVE-2014-3265

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-3265
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-3265
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-03192
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201405-385
value: MEDIUM

Trust: 0.6

VULHUB: VHN-71205
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-3265
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-03192
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-71205
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CNVD: CNVD-2014-03192 // VULHUB: VHN-71205 // JVNDB: JVNDB-2014-002551 // CNNVD: CNNVD-201405-385 // NVD: CVE-2014-3265

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-71205 // JVNDB: JVNDB-2014-002551 // NVD: CVE-2014-3265

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201405-385

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201405-385

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-002551

PATCH

title:Cisco Security Manager AUS Cross-Site Scripting Vulnerabilityurl:http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3265

Trust: 0.8

title:34274url:http://tools.cisco.com/security/center/viewAlert.x?alertId=34274

Trust: 0.8

title:Cisco Security Manage automatically upgrades patches for server cross-site scripting vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/45840

Trust: 0.6

sources: CNVD: CNVD-2014-03192 // JVNDB: JVNDB-2014-002551

EXTERNAL IDS

db:NVDid:CVE-2014-3265

Trust: 3.4

db:SECTRACKid:1030260

Trust: 1.1

db:BIDid:67499

Trust: 1.0

db:JVNDBid:JVNDB-2014-002551

Trust: 0.8

db:CNNVDid:CNNVD-201405-385

Trust: 0.7

db:CNVDid:CNVD-2014-03192

Trust: 0.6

db:CISCOid:20140519 CISCO SECURITY MANAGER AUS CROSS-SITE SCRIPTING VULNERABILITY

Trust: 0.6

db:VULHUBid:VHN-71205

Trust: 0.1

sources: CNVD: CNVD-2014-03192 // VULHUB: VHN-71205 // BID: 67499 // JVNDB: JVNDB-2014-002551 // CNNVD: CNNVD-201405-385 // NVD: CVE-2014-3265

REFERENCES

url:http://tools.cisco.com/security/center/content/ciscosecuritynotice/cve-2014-3265

Trust: 2.6

url:http://tools.cisco.com/security/center/viewalert.x?alertid=34274

Trust: 2.0

url:http://www.securitytracker.com/id/1030260

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-3265

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-3265

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: CNVD: CNVD-2014-03192 // VULHUB: VHN-71205 // BID: 67499 // JVNDB: JVNDB-2014-002551 // CNNVD: CNNVD-201405-385 // NVD: CVE-2014-3265

CREDITS

Cisco

Trust: 0.3

sources: BID: 67499

SOURCES

db:CNVDid:CNVD-2014-03192
db:VULHUBid:VHN-71205
db:BIDid:67499
db:JVNDBid:JVNDB-2014-002551
db:CNNVDid:CNNVD-201405-385
db:NVDid:CVE-2014-3265

LAST UPDATE DATE

2025-04-13T23:23:54.329000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2014-03192date:2014-05-23T00:00:00
db:VULHUBid:VHN-71205date:2016-09-07T00:00:00
db:BIDid:67499date:2014-05-19T00:00:00
db:JVNDBid:JVNDB-2014-002551date:2014-05-21T00:00:00
db:CNNVDid:CNNVD-201405-385date:2014-05-23T00:00:00
db:NVDid:CVE-2014-3265date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CNVDid:CNVD-2014-03192date:2014-05-23T00:00:00
db:VULHUBid:VHN-71205date:2014-05-20T00:00:00
db:BIDid:67499date:2014-05-19T00:00:00
db:JVNDBid:JVNDB-2014-002551date:2014-05-21T00:00:00
db:CNNVDid:CNNVD-201405-385date:2014-05-23T00:00:00
db:NVDid:CVE-2014-3265date:2014-05-20T11:13:38.013