MEDIUM · 4.3

CVE-2014-3313

Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, ak...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuo52582.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
CiscoSpa 301 1 Line Ip PhoneAll versions
CiscoSpa 303 3 Line Ip PhoneAll versions
CiscoSpa 501G 8-Line Ip PhoneAll versions
CiscoSpa 502G 1-Line Ip PhoneAll versions
CiscoSpa 504G 4-Line Ip PhoneAll versions
CiscoSpa 508G 8-Line Ip PhoneAll versions
CiscoSpa 509G 12-Line Ip PhoneAll versions
CiscoSpa 512G 1-Line Ip PhoneAll versions
CiscoSpa 514G 4-Line Ip PhoneAll versions
CiscoSpa 525G 5-Line Ip PhoneAll versions
CiscoSpa 525G2 5-Line Ip PhoneAll versions
CiscoSpa901 1-Line Ip PhoneAll versions
CiscoSpa922 1-Line Ip Phone With 1-Port EthernetAll versions
CiscoSpa941 4-Line Ip Phone With 1-Port EthernetAll versions
CiscoSpa942 4-Line Ip Phone With 2-Port SwitchAll versions
CiscoSpa962 6-Line Ip Phone With 2-Port SwitchAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-3313?

CVE-2014-3313 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the web user interface on Cisco Small Business SPA300 and SPA500 phones allows remote attackers to inject arbitrary web script or HTML via a crafted URL, ak...

How severe is CVE-2014-3313?

CVE-2014-3313 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-3313?

Check the references section above for vendor advisories and patch information. Affected products include: Cisco Spa 301 1 Line Ip Phone, Cisco Spa 303 3 Line Ip Phone, Cisco Spa 501G 8-Line Ip Phone, Cisco Spa 502G 1-Line Ip Phone, Cisco Spa 504G 4-Line Ip Phone.