HIGH · 7.5

CVE-2014-5417

Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MeinbergNtp Server Firmware-
MeinbergLantime M100<= 6.15.0.19
MeinbergLantime M200<= 6.15.0.19
MeinbergLantime M300<= 6.15.0.19
MeinbergLantime M3000<= 6.15.0.19
MeinbergLantime M400<= 6.15.0.19
MeinbergLantime M600<= 6.15.0.19
MeinbergLantime M900<= 6.15.0.19

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-5417?

CVE-2014-5417 is a vulnerability with a CVSS score of 7.5 (HIGH). Cross-site scripting (XSS) vulnerability in Meinberg NTP Server firmware on LANTIME M-Series devices 6.15.019 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified...

How severe is CVE-2014-5417?

CVE-2014-5417 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-5417?

Check the references section above for vendor advisories and patch information. Affected products include: Meinberg Ntp Server Firmware, Meinberg Lantime M100, Meinberg Lantime M200, Meinberg Lantime M300, Meinberg Lantime M3000.