Medium severity6.1NVD Advisory· Published Jan 31, 2020· Updated Jun 17, 2026
CVE-2014-3809
CVE-2014-3809
Description
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.
Affected products
5- cpe:2.3:o:nokia:1830_photonic_service_switch-16_firmware:*:*:*:*:*:*:*:*Range: <=6.0
- cpe:2.3:o:nokia:1830_photonic_service_switch-32_firmware:*:*:*:*:*:*:*:*Range: <=6.0
- cpe:2.3:o:nokia:1830_photonic_service_switch-4_firmware:*:*:*:*:*:*:*:*Range: <=6.0
- Alcatel-Lucent/1830 Photonic Service Switchdescription
- Range: <=6.0
Patches
Vulnerability mechanics
References
1- www.securityfocus.com/archive/1/534124nvdExploitThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.