Vulnslist

find the latest Cisco vulnerabilities

Cisco Building Broadband Service Manager Cross-Site Scripting Vulnerability

Cisco-SA-20080514-CVE-2008-2165 · Medium · Published · Updated

Cisco Building Broadband Service Manager (BBSM) 5.3 SP2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability exists due to an input validation error in certain web pages associated with the BBSM web interface.  An attacker could exploit this vulnerability by convincing an authenticated user to follow a crafted link designed to conduct the cross-site scripting attack.  Successful exploits could allow the attacker to execute arbitrary script code on the system with the privileges of the targeted user. Proof-of-concept URLs are available to demonstrate this vulnerability. Cisco confirmed this vulnerability in a Cisco bug ID and released a patch to correct it. Social engineering tactics must be employed to exploit this vulnerability because the attacker must convince a user to follow a malicious link sent via e-mail or other forms of messaging.  Attackers cannot exploit this vulnerability directly and must rely on user interaction, reducing the likelihood of an attack. Attackers may be able to gain access to user cookies and recently submitted data.  The attacker may also be able to take actions as the targeted user on the affected software.

Workarounds

Administrators are advised to apply BBSM patch 5322 to address this vulnerability.

Users are advised not to open e-mail messages from untrusted sources.

Users are advised not to follow unsolicited links.  Users should verify the authenticity of unexpected links prior to following them.

For additional information on cross-site scripting attacks and methods, users  are advised to reference the Cisco Applied Mitigation document Understanding Cross-Site Scripting Threat Vectorshttp://www.cisco.com/warp/public/707/cisco-air-20060922-understanding-xss.shtml .

CVEsCVE-2008-2165
Cisco Bug IDsNA
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C/CDP:N/TD:N/CR:ND/IR:ND/AR:ND
Product Names From Source
Cisco Building Broadband Service Manager (BBSM)

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Building Broadband Service Manager (BBSM) known_affected cisco_csaf CVE-2008-2165 1

Related Products

Product CVE Evidence
Cisco Building Broadband Service Manager (BBSM) CVE-2008-2165 Cisco OpenVuln