Vulnslist

find the latest Cisco vulnerabilities

Cisco Connected Grid Network Management System Cross-Site Scripting Vulnerabilities

Cisco-SA-20130401-CVE-2013-1171 · Medium · Published · Updated

Cisco Connected Grid Network Management System (CG-NMS) contains multiple vulnerabilities that could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco Connected Grid Network Management System is susceptible to cross-site scripting (XSS) vulnerabilities in the element list component. XSS attacks use obfuscation by encoding tags or malicious portions of the script using the Unicode method so that the link or HTML content is disguised to the end user browsing to the site. The origins of XSS attacks are difficult to identify using traceback methods because the vulnerable server is used to inject the malicious code to the users' browsers, thus concealing the identity of the malicious user. Cisco has confirmed these vulnerabilities in a security notice and software updates are available. To exploit this vulnerability, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link. Customers are advised to review the bug reports in the vendor announcements section for a current list of affected versions. Cisco indicates through the CVSS score that functional exploit code exists; however, the code is not known to be publicly available.

Workarounds

Administrators are advised to apply the appropriate updates.

Users are advised not to open e-mail messages from suspicious or unrecognized sources. If users cannot verify that links or attachments included in e-mail messages are safe, they are advised not to open them.

For additional information about cross-site scripting attacks and the methods used to exploit these vulnerabilities, see the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting (XSS) Threat Vectorshttp://www.cisco.com/en/US/products/cmb/cisco-amb-20060922-understanding-xss.html

Administrators are advised to monitor affected systems.

CVEsCVE-2013-1171
Cisco Bug IDsCSCue14517, CSCue14540, CSCue38853, CSCue38866, CSCue38868, CSCue38872, CSCue38881, CSCue38882, CSCue38884, CSCue38914
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C
Product Names From Source
Cisco Connected Grid Network Management System (CG-NMS)

CSAF Product Statuses

Product Status Source CVE Rows
Cisco Connected Grid Network Management System (CG-NMS) known_affected cisco_csaf CVE-2013-1171 1

Related Products

Product CVE Evidence
Cisco Connected Grid Network Management System (CG-NMS) CVE-2013-1171 Cisco OpenVuln