Vulnerability Details CVE-2014-3364
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Prime Security Manager (aka PRSM) 9.2.1-2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) Access Policies or (2) Device Summary Dashboard parameter, aka Bug ID CSCuq80661.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.9%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2014-3364
-
cpe:2.3:a:cisco:prime_security_manager:9.0
-
cpe:2.3:a:cisco:prime_security_manager:9.0.0
-
cpe:2.3:a:cisco:prime_security_manager:9.0.1-40
-
cpe:2.3:a:cisco:prime_security_manager:9.0.2-68
-
cpe:2.3:a:cisco:prime_security_manager:9.1
-
cpe:2.3:a:cisco:prime_security_manager:9.1.0
-
cpe:2.3:a:cisco:prime_security_manager:9.1.2-29
-
cpe:2.3:a:cisco:prime_security_manager:9.1.2-42
-
cpe:2.3:a:cisco:prime_security_manager:9.1.3-10
-
cpe:2.3:a:cisco:prime_security_manager:9.1.3-13
-
cpe:2.3:a:cisco:prime_security_manager:9.1.3-8
-
cpe:2.3:a:cisco:prime_security_manager:9.2
-
cpe:2.3:a:cisco:prime_security_manager:9.2.0
-
cpe:2.3:a:cisco:prime_security_manager:9.2.1-1
-
cpe:2.3:a:cisco:prime_security_manager:9.2.1-2