MEDIUM · 4.3

CVE-2012-3047

Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecifie...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoScientific Atlanta Dpc\/Epc 3208-
CiscoScientific Atlanta Dpc\/Epc2100-
CiscoScientific Atlanta Dpc\/Epc2202-
CiscoScientific Atlanta Dpc\/Epc2203-
CiscoScientific Atlanta Dpc\/Epc2325-
CiscoScientific Atlanta Dpc\/Epc2425-
CiscoScientific Atlanta Dpc\/Epc2434-
CiscoScientific Atlanta Dpc\/Epc2505-
CiscoScientific Atlanta Dpc\/Epc3010-
CiscoScientific Atlanta Dpc\/Epc3212-
CiscoScientific Atlanta Dpc2420-
CiscoScientific Atlanta Dpc3000\/Epc3000-
CiscoScientific Atlanta Dpc3008\/Epc3008-
CiscoScientific Atlanta Dpc3825-
CiscoScientific Atlanta Dpc3925-
CiscoScientific Atlanta Dpq\/Epq2160-
CiscoScientific Atlanta Dpq2202-
CiscoScientific Atlanta Dpq2425-
CiscoScientific Atlanta Dpq3212-
CiscoScientific Atlanta Dpq3925-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-3047?

CVE-2012-3047 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecifie...

How severe is CVE-2012-3047?

CVE-2012-3047 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-3047?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Scientific Atlanta Dpc\/Epc 3208, Cisco Scientific Atlanta Dpc\/Epc2100, Cisco Scientific Atlanta Dpc\/Epc2202, Cisco Scientific Atlanta Dpc\/Epc2203, Cisco Scientific Atlanta Dpc\/Epc2325.