VulnerabilityModified
CVE-2009-2119
Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.
MEDIUM 4.3EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in the login interface (my.logon.php3) in F5 FirePass SSL VPN 5.5 through 5.5.2 and 6.0 through 6.0.3 allows remote attackers to inject arbitrary web script or HTML via a base64-encoded xcho parameter.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- f5/firepass ssl vpn
- Source
- cve@mitre.org
References
- http://osvdb.org/55040
- http://secunia.com/advisories/35418Vendor Advisory
- http://secunia.com/advisories/35426Vendor Advisory
- http://www.securityfocus.com/archive/1/504232/100/0/threaded
- http://www.securityfocus.com/bid/35312
- http://www.securitytracker.com/id?1022387Patch
- http://www.vupen.com/english/advisories/2009/1570Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51064
- https://www.fox-it.com/nl/nieuws-en-events/nieuws/laatste-nieuws/nieuwsartikel/f5-firepass-cross-site-scripting-vulnerability/106Vendor Advisory
- https://www.fox-it.com/uploads/pdf/advisory_xss_f5_firepass.pdf
- http://osvdb.org/55040
- http://secunia.com/advisories/35418Vendor Advisory
- http://secunia.com/advisories/35426Vendor Advisory
- http://www.securityfocus.com/archive/1/504232/100/0/threaded
- http://www.securityfocus.com/bid/35312
- http://www.securitytracker.com/id?1022387Patch
- http://www.vupen.com/english/advisories/2009/1570Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51064
- https://www.fox-it.com/nl/nieuws-en-events/nieuws/laatste-nieuws/nieuwsartikel/f5-firepass-cross-site-scripting-vulnerability/106Vendor Advisory
- https://www.fox-it.com/uploads/pdf/advisory_xss_f5_firepass.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.