{ "id": "CVE-2014-0680", "sourceIdentifier": "ykramarz@cisco.com", "published": "2014-01-29T18:34:05.310", "lastModified": "2018-01-03T02:29:03.490", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Cross-site scripting (XSS) vulnerability in the HTTP control interface in the NAC Web Agent component in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCui15038." }, { "lang": "es", "value": "Vulnerabilidad de XSS en el control de interfaz HTTP en el componenete NAC Web Agent de Cisco Identity Services Engine (ISE) permite a atacantes remotos inyectar script Web o HTML arbitrario a trav\u00e9s de una URL manipulada, tambi\u00e9n conocido como Bug ID CSCui15038." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "NONE", "integrityImpact": "PARTIAL", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-79" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:h:cisco:identity_services_engine:-:*:*:*:*:*:*:*", "matchCriteriaId": "9A8A64C2-2A16-4A96-822D-2EFC3D61D58D" } ] } ] } ], "references": [ { "url": "http://tools.cisco.com/security/center/content/CiscoSecurityNotice/CVE-2014-0680", "source": "ykramarz@cisco.com", "tags": [ "Vendor Advisory" ] }, { "url": "http://tools.cisco.com/security/center/viewAlert.x?alertId=32617", "source": "ykramarz@cisco.com" }, { "url": "http://www.securityfocus.com/bid/65227", "source": "ykramarz@cisco.com" }, { "url": "http://www.securitytracker.com/id/1029701", "source": "ykramarz@cisco.com" } ] }