Vulnerability Description
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun91113.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Broadband Access Center Telco Wireless Software | - |
Related Weaknesses (CWE)
References
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2191Vendor Advisory
- http://www.securitytracker.com/id/1030198
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-2191Vendor Advisory
- http://www.securitytracker.com/id/1030198
FAQ
What is CVE-2014-2191?
CVE-2014-2191 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to inject arbitrary web script or HTML via an...
How severe is CVE-2014-2191?
CVE-2014-2191 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2191?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Broadband Access Center Telco Wireless Software.