Vulnerability Description
Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Emergency Responder | <= 8.6 |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2116Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=33641Vendor Advisory
- http://www.securityfocus.com/bid/66632
- http://www.securitytracker.com/id/1030019
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2116Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=33641Vendor Advisory
- http://www.securityfocus.com/bid/66632
- http://www.securitytracker.com/id/1030019
FAQ
What is CVE-2014-2116?
CVE-2014-2116 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cisco Emergency Responder (ER) 8.6 and earlier allows remote attackers to inject web pages and modify dynamic content via unspecified parameters, aka Bug ID CSCun37882.
How severe is CVE-2014-2116?
CVE-2014-2116 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2116?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Emergency Responder.