CVE-2014-2968
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.
Affected (3)
Products: Huawei: E355 Firmware, E355 Web Ui, E355
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 21.157.37.01.910 | |
| Version 11.001.08.00.03 | |
| Version ch1e355sm |
References (2)
Source: cret@cert.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.