CVE-2014-2045 PUBLISHED CVSS 6.099999904632568 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 300 allow remote attackers to inject arbitrary web script or HTML via the username when (1) logging in or (2) creating an account in the old interface, (3) username when creating an account in the new interface, (4) hostname in the old interface, (5) inspect parameter in the config module, (6) commands parameter in the atcommands tool, or (7) host parameter in the ping tool.

EPSS 4.34% · 88.8th percentile

Risk Scores

CVSS v3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
4.34%
88.8th percentile

Affected Products

VendorProductVersions
viprinetmultichannel_vpn_router_300_firmware2013070830, 2013080900
n/an/an/a

Timeline

References

Open in Interactive Console →