Cross-Site Scripting Vulnerability in NEC Platforms Calsos Products
CVE-2018-0614

6.1MEDIUM

What is CVE-2018-0614?

A cross-site scripting vulnerability exists in NEC Platforms' Calsos CSDX and CSDJ series products. This flaw allows remote attackers to inject arbitrary web scripts or HTML into user sessions. It affects several versions of CSDX and CSDJ products, potentially compromising the confidentiality and integrity of user data via malicious scripts executed in a web browser context. Users running affected versions should promptly assess their exposure and implement necessary security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Calsos CSDX and CSDJ series products CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.