ID

VAR-201803-1599


CVE

CVE-2018-0220


TITLE

Cisco Videoscape AnyRes Live Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2018-002672

DESCRIPTION

A vulnerability in the web-based management interface of Cisco Videoscape AnyRes Live could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvg87525. Cisco Videoscape AnyRes Live Contains a cross-site scripting vulnerability. Vendors have confirmed this vulnerability Bug ID CSCvg87525 It is released as.Information may be obtained and information may be altered. This can allow the attacker to steal cookie-based authentication credentials and launch other attacks. Cisco Videoscape AnyRes Live is a multi-format video encoder released by Cisco

Trust: 1.98

sources: NVD: CVE-2018-0220 // JVNDB: JVNDB-2018-002672 // BID: 103342 // VULHUB: VHN-118422

AFFECTED PRODUCTS

vendor:ciscomodel:videoscape anyres livescope:eqversion:9.7.6

Trust: 1.6

vendor:ciscomodel:videoscape anyres livescope: - version: -

Trust: 0.8

vendor:ciscomodel:videoscape anyres livescope:eqversion:0

Trust: 0.3

sources: BID: 103342 // JVNDB: JVNDB-2018-002672 // CNNVD: CNNVD-201803-247 // NVD: CVE-2018-0220

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-0220
value: MEDIUM

Trust: 1.0

NVD: CVE-2018-0220
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201803-247
value: MEDIUM

Trust: 0.6

VULHUB: VHN-118422
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2018-0220
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-118422
severity: LOW
baseScore: 3.5
vectorString: AV:N/AC:M/AU:S/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 6.8
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-0220
baseSeverity: MEDIUM
baseScore: 5.4
vectorString: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.3
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-118422 // JVNDB: JVNDB-2018-002672 // CNNVD: CNNVD-201803-247 // NVD: CVE-2018-0220

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-118422 // JVNDB: JVNDB-2018-002672 // NVD: CVE-2018-0220

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201803-247

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201803-247

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-002672

PATCH

title:cisco-sa-20180307-valurl:https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180307-val

Trust: 0.8

title:Cisco Videoscape AnyRes Live Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=78981

Trust: 0.6

sources: JVNDB: JVNDB-2018-002672 // CNNVD: CNNVD-201803-247

EXTERNAL IDS

db:NVDid:CVE-2018-0220

Trust: 2.8

db:BIDid:103342

Trust: 2.0

db:JVNDBid:JVNDB-2018-002672

Trust: 0.8

db:CNNVDid:CNNVD-201803-247

Trust: 0.7

db:VULHUBid:VHN-118422

Trust: 0.1

sources: VULHUB: VHN-118422 // BID: 103342 // JVNDB: JVNDB-2018-002672 // CNNVD: CNNVD-201803-247 // NVD: CVE-2018-0220

REFERENCES

url:https://tools.cisco.com/security/center/content/ciscosecurityadvisory/cisco-sa-20180307-val

Trust: 2.0

url:http://www.securityfocus.com/bid/103342

Trust: 1.7

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-0220

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-0220

Trust: 0.8

url:http://www.cisco.com/

Trust: 0.3

sources: VULHUB: VHN-118422 // BID: 103342 // JVNDB: JVNDB-2018-002672 // CNNVD: CNNVD-201803-247 // NVD: CVE-2018-0220

CREDITS

Cisco

Trust: 0.3

sources: BID: 103342

SOURCES

db:VULHUBid:VHN-118422
db:BIDid:103342
db:JVNDBid:JVNDB-2018-002672
db:CNNVDid:CNNVD-201803-247
db:NVDid:CVE-2018-0220

LAST UPDATE DATE

2024-11-23T21:39:31.847000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-118422date:2019-10-09T00:00:00
db:BIDid:103342date:2018-03-07T00:00:00
db:JVNDBid:JVNDB-2018-002672date:2018-04-23T00:00:00
db:CNNVDid:CNNVD-201803-247date:2019-10-17T00:00:00
db:NVDid:CVE-2018-0220date:2024-11-21T03:37:45.640

SOURCES RELEASE DATE

db:VULHUBid:VHN-118422date:2018-03-08T00:00:00
db:BIDid:103342date:2018-03-07T00:00:00
db:JVNDBid:JVNDB-2018-002672date:2018-04-23T00:00:00
db:CNNVDid:CNNVD-201803-247date:2018-03-09T00:00:00
db:NVDid:CVE-2018-0220date:2018-03-08T07:29:01.097