Vulnerability Description
Cross-site scripting (XSS) vulnerability in the vCloud Director component in Cisco Nexus 1000V InterCloud for VMware allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCuq90524.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Cisco Nexus 1000V Intercloud | - |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/61426
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3367Vendor Advisory
- http://www.securityfocus.com/bid/70010
- http://www.securitytracker.com/id/1030881
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96126
- http://secunia.com/advisories/61426
- http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-3367Vendor Advisory
- http://www.securityfocus.com/bid/70010
- http://www.securitytracker.com/id/1030881
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96126
FAQ
What is CVE-2014-3367?
CVE-2014-3367 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the vCloud Director component in Cisco Nexus 1000V InterCloud for VMware allows remote attackers to inject arbitrary web script or HTML via an unspecified v...
How severe is CVE-2014-3367?
CVE-2014-3367 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3367?
Check the references section above for vendor advisories and patch information. Affected products include: Cisco Cisco Nexus 1000V Intercloud.