CVE-2017-5256
Last modified
CVE-2017-5256 is a vulnerability of currently unknown severity. In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site scripting (XSS) injection.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cambiumnetworks | Epmp 1000 Firmware | <= 3.5 |
| Cambiumnetworks | Epmp 2000 Firmware | <= 3.5 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-5256?
How severe is CVE-2017-5256?
How do I fix CVE-2017-5256?
Are you affected by CVE-2017-5256?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
