PT-2016-4723 · Cisco · Cisco Information Server
Published
2016-04-30
·
Updated
2016-05-04
·
CVE-2016-1343
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Information Server (CIS) version 6.2
Description
The issue allows remote attackers to read arbitrary files or cause a denial of service due to an XML External Entity (XXE) issue. This is related to the XML parser in Cisco Information Server.
Recommendations
For Cisco Information Server (CIS) version 6.2, consider disabling the XML parser functionality until a patch is available to prevent exploitation of the XXE issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cisco Information Server