ID

VAR-201407-0443


CVE

CVE-2014-2975


TITLE

Silver Peak VX Cross-Site Scripting Vulnerability

Trust: 1.2

sources: CNVD: CNVD-2014-04722 // CNNVD: CNNVD-201407-661

DESCRIPTION

Cross-site scripting (XSS) vulnerability in php/user_account.php in Silver Peak VX before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via the user_id parameter. Silver Peak VX is a virtual WAN optimization solution. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 3.15

sources: NVD: CVE-2014-2975 // CERT/CC: VU#867980 // JVNDB: JVNDB-2014-003602 // CNVD: CNVD-2014-04722 // BID: 68923

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2014-04722

AFFECTED PRODUCTS

vendor:silver peakmodel:vxscope:eqversion:6.2.2.0_47968

Trust: 1.6

vendor:silver peakmodel:vxscope:lteversion:6.2.4

Trust: 1.0

vendor:silver peakmodel: - scope: - version: -

Trust: 0.8

vendor:silver peakmodel:vxscope:ltversion:6.2.4

Trust: 0.8

vendor:silver peakmodel: - scope:eqversion:vx<6.2.4

Trust: 0.6

vendor:silver peakmodel:6.2.2.0 47968scope:eqversion:vx

Trust: 0.6

vendor:silver peakmodel:vxscope:eqversion:6.2.4

Trust: 0.6

sources: CERT/CC: VU#867980 // CNVD: CNVD-2014-04722 // JVNDB: JVNDB-2014-003602 // CNNVD: CNNVD-201407-661 // NVD: CVE-2014-2975

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-2975
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-2975
value: MEDIUM

Trust: 0.8

CNVD: CNVD-2014-04722
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-201407-661
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2014-2975
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2014-04722
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2014-04722 // JVNDB: JVNDB-2014-003602 // CNNVD: CNNVD-201407-661 // NVD: CVE-2014-2975

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2014-003602 // NVD: CVE-2014-2975

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201407-661

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201407-661

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-003602

PATCH

title:VX Softwareurl:http://www.silver-peak.com/products-solutions/wan-optimization/vx-software

Trust: 0.8

title:Patch for Silver Peak VX Cross-Site Scripting Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/48054

Trust: 0.6

sources: CNVD: CNVD-2014-04722 // JVNDB: JVNDB-2014-003602

EXTERNAL IDS

db:CERT/CCid:VU#867980

Trust: 3.8

db:NVDid:CVE-2014-2975

Trust: 3.3

db:BIDid:68923

Trust: 1.9

db:JVNid:JVNVU97348300

Trust: 0.8

db:JVNDBid:JVNDB-2014-003602

Trust: 0.8

db:CNVDid:CNVD-2014-04722

Trust: 0.6

db:CNNVDid:CNNVD-201407-661

Trust: 0.6

sources: CERT/CC: VU#867980 // CNVD: CNVD-2014-04722 // BID: 68923 // JVNDB: JVNDB-2014-003602 // CNNVD: CNNVD-201407-661 // NVD: CVE-2014-2975

REFERENCES

url:http://www.kb.cert.org/vuls/id/867980

Trust: 3.0

url:http://www.securityfocus.com/bid/68923

Trust: 1.0

url:http://www.silver-peak.com/products-solutions/wan-optimization/vx-software

Trust: 0.8

url:http://cwe.mitre.org/data/definitions/79.html

Trust: 0.8

url:http://cwe.mitre.org/data/definitions/352.html

Trust: 0.8

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-2975

Trust: 0.8

url:http://jvn.jp/vu/jvnvu97348300/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-2975

Trust: 0.8

sources: CERT/CC: VU#867980 // CNVD: CNVD-2014-04722 // JVNDB: JVNDB-2014-003602 // CNNVD: CNNVD-201407-661 // NVD: CVE-2014-2975

CREDITS

William Costa

Trust: 0.3

sources: BID: 68923

SOURCES

db:CERT/CCid:VU#867980
db:CNVDid:CNVD-2014-04722
db:BIDid:68923
db:JVNDBid:JVNDB-2014-003602
db:CNNVDid:CNNVD-201407-661
db:NVDid:CVE-2014-2975

LAST UPDATE DATE

2025-04-13T23:18:21.260000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#867980date:2014-07-28T00:00:00
db:CNVDid:CNVD-2014-04722date:2014-07-31T00:00:00
db:BIDid:68923date:2014-07-28T00:00:00
db:JVNDBid:JVNDB-2014-003602date:2014-07-30T00:00:00
db:CNNVDid:CNNVD-201407-661date:2014-07-29T00:00:00
db:NVDid:CVE-2014-2975date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:CERT/CCid:VU#867980date:2014-07-28T00:00:00
db:CNVDid:CNVD-2014-04722date:2014-07-31T00:00:00
db:BIDid:68923date:2014-07-28T00:00:00
db:JVNDBid:JVNDB-2014-003602date:2014-07-30T00:00:00
db:CNNVDid:CNNVD-201407-661date:2014-07-29T00:00:00
db:NVDid:CVE-2014-2975date:2014-07-28T17:55:07.107