First published: Wed Mar 06 2013(Updated: )
The XML parser in Cisco Security Monitoring, Analysis, and Response System (MARS) allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCue55093.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Security Monitoring Analysis and Response System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1140 is classified as a Medium severity vulnerability.
CVE-2013-1140 allows remote attackers to read arbitrary files on the system via an XML External Entity (XXE) attack.
All versions of Cisco Security Monitoring Analysis and Response System that are impacted by this issue are affected.
To mitigate CVE-2013-1140, update your Cisco Security Monitoring Analysis and Response System to a patched version provided by Cisco.
Yes, Cisco has released patches for CVE-2013-1140 that should be applied to affected systems.