CVE-2015-2850

Cross-site scripting (XSS) vulnerability in index-login.ant in the ANTlabs InnGate firmware on IG 3100, InnGate 3.01 E, InnGate 3.10 E, InnGate 3.10 M, SG 4, and SSG 4 devices allows remote attackers to inject arbitrary web script or HTML via the msg parameter.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
certccCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
antlabsinngate_ig_3.01_e
-
antlabsinngate_ig_3.10_e
-
antlabsinngate_ig_3.10_m
-
antlabsinngate_ig_3100
-
antlabsinngate_sg_4
-
antlabsinngate_ssg_4
-
𝑥
= Vulnerable software versions