CVE-2018-0614

Cross-site scripting vulnerability in NEC Platforms Calsos CSDX and CSDJ series products (CSDX 1.37210411 and earlier, CSDX(P) 4.37210411 and earlier, CSDX(D) 3.37210411 and earlier, CSDX(S) 2.37210411 and earlier, CSDJ-B 01.03.00 and earlier, CSDJ-H 01.03.00 and earlier, CSDJ-D 01.03.00 and earlier, CSDJ-A 03.00.00) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
necplatformscalsos_csdx_firmware
𝑥
≤ 1.37210411
necplatformscalsos_csdx\(p\)_firmware
𝑥
≤ 4.37210411
necplatformscalsos_csdx\(s\)_firmware
𝑥
≤ 2.37210411
necplatformscalsos_csdx\(d\)_firmware
𝑥
≤ 3.37210411
necplatformscalsos_csdj-b_firmware
𝑥
≤ 01.03.00
necplatformscalsos_csdj-d_firmware
𝑥
≤ 01.03.00
necplatformscalsos_csdj-h_firmware
𝑥
≤ 01.03.00
necplatformscalsos_csdj-a_firmware
𝑥
≤ 03.00.00
𝑥
= Vulnerable software versions