[Japanese]
|
JVNDB-2009-000006
|
Cisco IOS cross-site scripting vulnerability
|
The web-based interface implemented in Cisco IOS is vulnerable to cross-site scripting.
Some versions of the Cisco IOS provide a web-based interface to configure the device. This web-based interface contains a cross-site scripting vulnerability.
A wide range of versions are affected.
If the web-based interface is disabled, it is not affected. Some versions of the Cisco IOS have the web-based interface enabled by default.
For more information, refer to the information provided by Cisco.
NOBUHIRO TSUJI of NTT DATA SECURITY CORPORATION reported this vulnerability to IPA.
JPCERT/CC coordinated with the vendor under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 4.3 (Medium) [IPA Score]
- Access Vector: Network
- Access Complexity: Medium
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
Cisco Systems, Inc.
- Cisco IOS 11.0 through 12.4
|
|
An arbitrary script may be executed on the user's web browser.
|
[Update the Software]
Apply the latest firmware provided by Cisco.
[Workaround]
The users who are not able to update to the latest firmware should disable the web-based interface to mitigate this vulnerability.
|
Cisco Systems, Inc.
|
- Cross-site Scripting(CWE-79) [IPA Evaluation]
|
- CVE-2008-3821
|
- JVN : JVN#28344798
- National Vulnerability Database (NVD) : CVE-2008-3821
- JVN iPedia (Japanese) : JVNDB-2009-000006
|
- [2009/01/15]
Web page published
|