Medium severity5.4NVD Advisory· Published Apr 13, 2017· Updated May 13, 2026
CVE-2014-3887
CVE-2014-3887
Description
Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-4713.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ioplaza.jp/shop/contents/rdiskmanual.aspxnvdPatchVendor Advisory
- jvn.jp/en/jp/JVN74608669/index.htmlnvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.