CVE-2017-14386

The web user interface of Dell 2335dn and 2355dn Multifunction Laser Printers, firmware versions prior to V2.70.06.26 A13 and V2.70.45.34 A10 respectively, are affected by a cross-site scripting vulnerability. Attackers could potentially exploit this vulnerability to execute arbitrary HTML or JavaScript code in the user's browser session in the context of the affected website.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:2355dn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:2355dn:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:dell:2335dn_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:2335dn:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:12

Type Values Removed Values Added
References () http://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=782W3 - Patch, Vendor Advisory () http://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=782W3 - Patch, Vendor Advisory
References () http://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=CG55V - Patch, Vendor Advisory () http://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=CG55V - Patch, Vendor Advisory

Information

Published : 2017-12-07 19:29

Updated : 2024-11-21 03:12


NVD link : CVE-2017-14386

Mitre link : CVE-2017-14386

CVE.ORG link : CVE-2017-14386


JSON object : View

Products Affected

dell

  • 2335dn
  • 2355dn
  • 2355dn_firmware
  • 2335dn_firmware
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')