Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-31734

Опубликовано: 20 июн. 2022
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affected firmware is prior to 12.2(50)SY released in 2011, and Cisco Catalyst 2940 Series Switches have been retired since January 2015

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:cisco:ws-c2940-8tf-s_firmware:*:*:*:*:*:*:*:*
Версия до 12.2\(50\)sy (исключая)
cpe:2.3:h:cisco:ws-c2940-8tf-s:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:cisco:ws-c2940-8tt-s_firmware:*:*:*:*:*:*:*:*
Версия до 12.2\(50\)sy (исключая)
cpe:2.3:h:cisco:ws-c2940-8tt-s:-:*:*:*:*:*:*:*

EPSS

Процентиль: 73%
0.00779
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
github
больше 3 лет назад

** Unsupported When Assigned ** Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affected firmware is prior to 12.2(50)SY released in 2011, and Cisco Catalyst 2940 Series Switches have been retired since January 2015.

CVSS3: 6.1
fstec
больше 3 лет назад

Уязвимость микропрограммного обеспечения коммутаторов Cisco Catalyst 2940, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 73%
0.00779
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79