CVE-2016-1396

Description

Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux82583.

Risk Information

Base Score
6.1
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.25

Associated Vulnerability

VulnerabilityOS Platform
Cisco RV110W, RV130W, and RV215W Routers Cross-Site Scripting Vulnerability For Cisco Small Business RV Series RoutersNCM
Cisco RV110W, RV130W, and RV215W Routers Cross-Site Scripting Vulnerability For Cisco Application Extension PlatformNCM
Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability (CVE-2016-1396)NCM

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1705925Security Update for Cisco Small Business RV Series Routers 1.0.3.16
PATCH-1705914Security Update for Cisco Application Extension Platform 1.0.3.16

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234