Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-26081

Опубликовано: 18 нояб. 2020
Источник: nvd
CVSS3: 6.1
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web UI. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information on an affected system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cisco:iot_field_network_director:*:*:*:*:*:*:*:*
Версия до 4.6.1 (исключая)

EPSS

Процентиль: 37%
0.00153
Низкий

6.1 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-74
CWE-74

Связанные уязвимости

github
больше 3 лет назад

Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient validation of user-supplied input that is processed by the web UI. An attacker could exploit these vulnerabilities by persuading a user to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive, browser-based information on an affected system.

CVSS3: 6.1
fstec
почти 5 лет назад

Уязвимость веб-интерфейса программного средства управления сетью IoT Field Network Director, позволяющая нарушителю осуществить межсайтовую сценарную атаку

EPSS

Процентиль: 37%
0.00153
Низкий

6.1 Medium

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-74
CWE-74