MEDIUM · 6.1

CVE-2014-6189

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 ...

Vulnerability Description

Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS Score

6.1

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
IbmSecurity Network Protection 4100 Firmware5.2
IbmSecurity Network Protection 4100-
IbmSecurity Network Protection 3100 Firmware5.2
IbmSecurity Network Protection 3100-
IbmSecurity Network Protection 5100 Firmware5.2
IbmSecurity Network Protection 5100-
IbmSecurity Network Protection 7100 Firmware5.2
IbmSecurity Network Protection 7100-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-6189?

CVE-2014-6189 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting (XSS) vulnerability in IBM Security Network Protection 3100, 4100, 5100, and 7100 devices with firmware 5.2 before 5.2.0.0-ISS-XGS-All-Models-Hotfix-FP0008 and 5.3 before 5.3.0.5 ...

How severe is CVE-2014-6189?

CVE-2014-6189 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-6189?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Security Network Protection 4100 Firmware, Ibm Security Network Protection 4100, Ibm Security Network Protection 3100 Firmware, Ibm Security Network Protection 3100, Ibm Security Network Protection 5100 Firmware.