CVE-2014-0332
Estado: ModificadaMedia (4.3)—
Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.76%
- Percentil entre todas las CVEs puntuadas: 86
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-79
Referencias
- http://osvdb.org/103216
- http://www.kb.cert.org/vuls/id/727318
- http://www.securityfocus.com/bid/65498
- http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91062
- http://osvdb.org/103216
- http://www.kb.cert.org/vuls/id/727318
- http://www.securityfocus.com/bid/65498
- http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91062
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-0332",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cret@cert.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-02-14T16:55:08.030",
"references": [
{
"url": "http://osvdb.org/103216",
"tags": [
"Broken Link"
],
"source": "cret@cert.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/727318",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cret@cert.org"
},
{
"url": "http://www.securityfocus.com/bid/65498",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cret@cert.org"
},
{
"url": "http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf",
"tags": [
"Vendor Advisory"
],
"source": "cret@cert.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/91062",
"tags": [
"VDB Entry"
],
"source": "cret@cert.org"
},
{
"url": "http://osvdb.org/103216",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/727318",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/65498",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/91062",
"tags": [
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action."
},
{
"lang": "es",
"value": "Vulnerabilidad de XSS en mainPage en Dell SonicWALL GMS anterior a 7.1 SP2, SonicWALL Analyzer anterior a 7.1 SP2 y SonicWALL UMA E5000 anterior a 7.1 SP2 podría permitir a atacantes remotos inyectar script Web o HTML arbitrarios a través del parámetro node_id en una acción ScreenDisplayManager genNetwork."
}
],
"lastModified": "2026-06-17T00:02:48.500",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:global_management_system:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CEF95BB8-DF0B-4131-8A89-82DE559CC09B"
},
{
"criteria": "cpe:2.3:a:sonicwall:global_management_system:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF555F86-D3E0-4763-9E9A-C26D5C986FC4"
},
{
"criteria": "cpe:2.3:a:sonicwall:global_management_system:7.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "418595FE-EBFA-4B1D-A479-171BBD56279A"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sonicwall:uma_e5000:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D8F6C2F1-8C1A-4BAD-8F49-464258B09354"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:analyzer:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A9ABA5C-59AF-496A-B22E-0C88892EC8FD"
},
{
"criteria": "cpe:2.3:a:sonicwall:analyzer:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8078DCDB-FC88-41C8-BE14-688B5F4911E1"
},
{
"criteria": "cpe:2.3:a:sonicwall:analyzer:7.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "19E54EA9-F9F8-47FA-9F31-C05C2AE59539"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sonicwall:global_management_system:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CEF95BB8-DF0B-4131-8A89-82DE559CC09B"
},
{
"criteria": "cpe:2.3:a:sonicwall:global_management_system:7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF555F86-D3E0-4763-9E9A-C26D5C986FC4"
},
{
"criteria": "cpe:2.3:a:sonicwall:global_management_system:7.1:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "418595FE-EBFA-4B1D-A479-171BBD56279A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cret@cert.org"
}