First published: Wed Feb 22 2017(Updated: )
A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5).
Credit: ykramarz@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cisco Secure Access Control Server | =5.8\(2.5\) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3838 is considered a medium severity vulnerability due to its potential for exploitation through DOM-based cross-site scripting.
To fix CVE-2017-3838, you should upgrade to a later version of Cisco Secure Access Control System that addresses this vulnerability.
CVE-2017-3838 affects users of Cisco Secure Access Control System version 5.8(2.5) and earlier.
CVE-2017-3838 allows an attacker to conduct a DOM-based cross-site scripting (XSS) attack.
Yes, CVE-2017-3838 can be exploited by an unauthenticated remote attacker.