CVE-2017-5256
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD
Description
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.
Affected (2)
Products: Cambiumnetworks: Epmp 1000 Firmware, Epmp 2000 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Cambiumnetworks Epmp 1000 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.5 |
| Running on/with | Platform Versions |
|---|---|
Cambiumnetworks Epmp 2000 | All versions |
References (2)
Source: cve@rapid7.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.