Vulnslist

Cisco vulnerabilities by product, model, software, and advisory.

Cisco Video Surveillance 5000 Series HD IP Dome Camera Multiple Cross-Site Scripting Vulnerabilities

Cisco-SA-20140127-CVE-2014-0673 · Medium · Published · Updated

Multiple vulnerabilities in the web user interface of the Cisco Video Surveillance 5000 Series HD IP Dome Cameras could allow an unauthenticated, remote attacker to execute a cross-site scripting (XSS) attack. The vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a crafted URL. Cisco has confirmed the vulnerabilities in a security notice; however, software updates are not available. To exploit these vulnerabilities, the attacker may provide a link that directs a user to a malicious site and use misleading language or instructions to persuade the user to follow the provided link.

Cisco advisory · CSAF JSON

Workarounds

Administrators are advised to contact the vendor regarding future updates and releases.

Users are advised not to visit websites or follow links that have suspicious characteristics or cannot be verified as safe.

For additional information about XSS attacks and the methods used to exploit these vulnerabilities, see the Cisco Applied Mitigation Bulletin Understanding Cross-Site Scripting (XSS) Threat Vectors["http://www.cisco.com/en/US/products/cmb/cisco-amb-20060922-understanding-xss.html"].

Administrators may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Administrators are advised to monitor affected systems.

CVEsCVE-2014-0673
Cisco Bug IDsCSCud10943, CSCud10950
CVSS ScoreBase 4.3
Base 4.3 AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:U/RC:C
Product Names From Source
Cisco Video Surveillance 5000 Series HD IP Dome Camera Firmware

Related Products

Product CVE Evidence
Cisco Video Surveillance 5000 Series HD IP Dome Camera Firmware CVE-2014-0673 Cisco OpenVuln