The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A13 and V2.70.45.34 A10 respectively, are affected by a cross-site scripting vulnerability. Attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.
References
Link | Resource |
---|---|
http://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=CG55V | Patch Vendor Advisory |
http://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=782W3 | Patch Vendor Advisory |
Information
Published : 2017-12-07 11:29
Updated : 2017-12-27 08:12
NVD link : CVE-2017-14386
Mitre link : CVE-2017-14386
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
dell
- 2335dn
- 2355dn
- 2335dn_firmware
- 2355dn_firmware