Vulnerability Description
Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and Content Security Management Appliance (SMA) 8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, as demonstrated by the date_range parameter to monitor/reports/overview on the IronPort ESA, aka Bug IDs CSCun07998, CSCun07844, and CSCun07888.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Ironport Asyncos | <= 8.0 |
| Cisco | Web Security Appliance | - |
| Cisco | Content Security Management Appliance | - |
| Cisco | Email Security Appliance Firmware | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/127004/Cisco-Ironport-Email-Security-Virtua
- http://seclists.org/fulldisclosure/2014/Jun/57ExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/58296Permissions Required
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3289Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34569Vendor Advisory
- http://www.kb.cert.org/vuls/id/613308
- http://www.securityfocus.com/bid/67943Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030407Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/127004/Cisco-Ironport-Email-Security-Virtua
- http://seclists.org/fulldisclosure/2014/Jun/57ExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/58296Permissions Required
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3289Vendor Advisory
- http://tools.cisco.com/security/center/viewAlert.x?alertId=34569Vendor Advisory
- http://www.kb.cert.org/vuls/id/613308
- http://www.securityfocus.com/bid/67943Third Party AdvisoryVDB Entry
FAQ
What is CVE-2014-3289?
CVE-2014-3289 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the web management interface in Cisco AsyncOS on the Email Security Appliance (ESA) 8.0, Web Security Appliance (WSA) 8.0 (.5 Hot Patch 1) and earlier, and ...
How severe is CVE-2014-3289?
CVE-2014-3289 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3289?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Ironport Asyncos, Cisco Web Security Appliance, Cisco Content Security Management Appliance, Cisco Email Security Appliance Firmware.