CVE-2014-0673
Last modified
CVE-2014-0673 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.. EPSS estimates a 2.23% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cisco | Video Surveillance Indoor Fixed Dome Ip Hd Camera | 5010 |
| Cisco | Video Surveillance Indoor Fixed Dome Ip Hd Camera | 5011 |
References
- http://osvdb.org/102557Broken Link
- http://secunia.com/advisories/56552Permissions Required
- http://www.securityfocus.com/bid/65145Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029689Third Party Advisory, VDB Entry
- http://osvdb.org/102557Broken Link
- http://secunia.com/advisories/56552Permissions Required
- http://www.securityfocus.com/bid/65145Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029689Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-0673?
How severe is CVE-2014-0673?
How do I fix CVE-2014-0673?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-0667The RMI interface in Cisco Secure Access Control System (ACS…
- CVE-2014-0668Cross-site scripting (XSS) vulnerability in the portal in Ci…
- CVE-2014-0669The Wireless Session Protocol (WSP) feature in the Gateway G…
- CVE-2014-0670Cross-site scripting (XSS) vulnerability in the Search and P…
- CVE-2014-0671Open redirect vulnerability in Cisco MediaSense allows remot…
- CVE-2014-0672The Search and Play interface in Cisco MediaSense does not p…
- CVE-2014-0674Cisco Video Surveillance Operations Manager (VSOM) does not …
- CVE-2014-0675The Expressway component in Cisco TelePresence Video Communi…
- CVE-2014-0676Cisco NX-OS allows local users to bypass intended TACACS+ co…
- CVE-2014-0677The Label Distribution Protocol (LDP) functionality in Cisco…
- CVE-2014-0678The portal interface in Cisco Secure Access Control System (…
- CVE-2014-0679Cisco Prime Infrastructure 1.2 and 1.3 before 1.3.0.20-2, 1.…
Are you affected by CVE-2014-0673?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
