CVE-2014-3887 describes a Cross-Site Scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware versions prior to 1.05e1-2.0.5, allowing authenticated attackers to inject malicious web scripts. This vulnerability is a result of an incomplete fix for a previous XSS issue (CVE-2013-4713). Rated as MEDIUM severity with a CVSS score of 5.4, this vulnerability requires user authentication and interaction (UI:R) to exploit, but can be carried out over the network (AV:N). Successful exploitation could lead to limited confidentiality and integrity impacts (C:L/I:L) due to arbitrary web script execution. There is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. The vulnerability has received minimal community discussion and media coverage, indicating low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.05e1-2.0.5CPE matchmatch criteria | cpe:2.3:o:iodata:rockdisk_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.