CVE-2015-6346: XSS
Published Oct 30, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
1 affected component
Cisco Secure Access Control Server=5.7.0.15
Event History
Oct 30, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-6346?
CVE-2015-6346 has a high severity rating due to its potential for remote attacks through cross-site scripting.
2
How do I fix CVE-2015-6346?
To mitigate CVE-2015-6346, upgrade to a patched version of Cisco Secure Access Control Server above 5.7(0.15).
3
What type of vulnerability is CVE-2015-6346?
CVE-2015-6346 is a cross-site scripting (XSS) vulnerability allowing attackers to inject malicious scripts.
4
Who is affected by CVE-2015-6346?
Cisco Secure Access Control Server version 5.7(0.15) users are affected by CVE-2015-6346.
5
Can CVE-2015-6346 lead to data theft?
Yes, CVE-2015-6346 could allow attackers to execute scripts that may lead to data theft.