First published: Fri Jul 12 2013(Updated: )
Cross-site scripting (XSS) vulnerability in Administration pages in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCud75165.
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3422 is categorized as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To mitigate CVE-2013-3422, it is recommended to apply the latest patches provided by Cisco for the Secure Access Control System.
CVE-2013-3422 affects users of Cisco Secure Access Control System where the Administration pages are exposed.
If exploited, CVE-2013-3422 could allow attackers to inject arbitrary web scripts or HTML, potentially compromising user sessions.
CVE-2013-3422 was disclosed in July 2013 as a vulnerability affecting Cisco products.