PT-2017-16135 · Cisco · Cisco Secure Access Control System

Published

2017-02-22

·

Updated

2019-10-03

·

CVE-2017-3839

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco Secure Access Control System (ACS) version 5.8(2.5)
Description An XML External Entity issue in the web-based user interface could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system.
Recommendations For version 5.8(2.5), at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-3839

Affected Products

Cisco Secure Access Control System