Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-14386

Опубликовано: 07 дек. 2017
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A13 and V2.70.45.34 A10 respectively, are affected by a cross-site scripting vulnerability. Attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:dell:2355dn_firmware:*:*:*:*:*:*:*:*
Версия до 2.70.45.34_a10 (исключая)
cpe:2.3:h:dell:2355dn:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:dell:2335dn_firmware:*:*:*:*:*:*:*:*
Версия до 2.70.06.26_a13 (исключая)
cpe:2.3:h:dell:2335dn:-:*:*:*:*:*:*:*

EPSS

Процентиль: 53%
0.00307
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A13 and V2.70.45.34 A10 respectively, are affected by a cross-site scripting vulnerability. Attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.

EPSS

Процентиль: 53%
0.00307
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79