SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-2968

Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.

MEDIUM 4.3EPSS 0.80%

Does this matter?

Lower severity and a low EPSS score (0.80%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary web script or HTML via an SMS message.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
0.80% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
huawei/e355 web ui · huawei/e355 firmware · huawei/e355
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.