{"api_version":"1","generated_at":"2026-07-23T19:55:44+00:00","cve":"CVE-2014-0332","urls":{"html":"https://cve.report/CVE-2014-0332","api":"https://cve.report/api/cve/CVE-2014-0332.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-0332","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-0332"},"summary":{"title":"CVE-2014-0332","description":"Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action.","state":"PUBLISHED","assigner":"certcc","published_at":"2014-02-14 16:55:08","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.kb.cert.org/vuls/id/727318","name":"http://www.kb.cert.org/vuls/id/727318","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"Vulnerability Note VU#727318 - DELL SonicWALL GMS/Analyzer/UMA contains a cross-site scripting (XSS) vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91062","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91062","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf","name":"http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Page Not Found","mime":"application/pdf","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/65498","name":"http://www.securityfocus.com/bid/65498","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Multiple Dell SonicWALL Products '/sgms/mainPage' Page Cross Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/103216","name":"http://osvdb.org/103216","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-0332","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0332","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"332","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"analyzer","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"332","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"analyzer","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"332","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"analyzer","cpe6":"7.1","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"332","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"global_management_system","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"332","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"global_management_system","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"332","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sonicwall","cpe5":"global_management_system","cpe6":"7.1","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"332","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"sonicwall","cpe5":"uma_e5000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T09:13:09.580Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"65498","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/65498"},{"name":"VU#727318","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/727318"},{"name":"sonicwall-cve20140332-nodeid-xss(91062)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91062"},{"name":"103216","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/103216"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-02-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"65498","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/65498"},{"name":"VU#727318","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/727318"},{"name":"sonicwall-cve20140332-nodeid-xss(91062)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91062"},{"name":"103216","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/103216"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2014-0332","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"65498","refsource":"BID","url":"http://www.securityfocus.com/bid/65498"},{"name":"VU#727318","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/727318"},{"name":"sonicwall-cve20140332-nodeid-xss(91062)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/91062"},{"name":"103216","refsource":"OSVDB","url":"http://osvdb.org/103216"},{"name":"http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf","refsource":"CONFIRM","url":"http://www.sonicwall.com/us/shared/download/Support_Bulletin_GMS_Vulnerability_XSS_Resolved_in_7.1_SP2_and_7.2.pdf"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2014-0332","datePublished":"2014-02-14T16:00:00.000Z","dateReserved":"2013-12-05T00:00:00.000Z","dateUpdated":"2024-08-06T09:13:09.580Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-02-14 16:55:08","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:global_management_system:7.0:*:*:*:*:*:*:*","matchCriteriaId":"CEF95BB8-DF0B-4131-8A89-82DE559CC09B"},{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:global_management_system:7.1:*:*:*:*:*:*:*","matchCriteriaId":"AF555F86-D3E0-4763-9E9A-C26D5C986FC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:global_management_system:7.1:sp1:*:*:*:*:*:*","matchCriteriaId":"418595FE-EBFA-4B1D-A479-171BBD56279A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:sonicwall:uma_e5000:-:*:*:*:*:*:*:*","matchCriteriaId":"D8F6C2F1-8C1A-4BAD-8F49-464258B09354"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:analyzer:7.0:*:*:*:*:*:*:*","matchCriteriaId":"7A9ABA5C-59AF-496A-B22E-0C88892EC8FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:analyzer:7.1:*:*:*:*:*:*:*","matchCriteriaId":"8078DCDB-FC88-41C8-BE14-688B5F4911E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:analyzer:7.1:sp1:*:*:*:*:*:*","matchCriteriaId":"19E54EA9-F9F8-47FA-9F31-C05C2AE59539"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:global_management_system:7.0:*:*:*:*:*:*:*","matchCriteriaId":"CEF95BB8-DF0B-4131-8A89-82DE559CC09B"},{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:global_management_system:7.1:*:*:*:*:*:*:*","matchCriteriaId":"AF555F86-D3E0-4763-9E9A-C26D5C986FC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:sonicwall:global_management_system:7.1:sp1:*:*:*:*:*:*","matchCriteriaId":"418595FE-EBFA-4B1D-A479-171BBD56279A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"332","Ordinal":"1","Title":"CVE-2014-0332","CVE":"CVE-2014-0332","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"332","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in mainPage in Dell SonicWALL GMS before 7.1 SP2, SonicWALL Analyzer before 7.1 SP2, and SonicWALL UMA E5000 before 7.1 SP2 might allow remote attackers to inject arbitrary web script or HTML via the node_id parameter in a ScreenDisplayManager genNetwork action.","Type":"Description","Title":"CVE-2014-0332"},{"CveYear":"2014","CveId":"332","Ordinal":"2","NoteData":"2014-02-14","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"332","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}