CVE-2018-0207: XEE
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit this vulnerability by convincing the administrator of an affected system to import a crafted XML file. Cisco Bug IDs: CSCve70595.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-0207?
CVE-2018-0207 has a severity rating of critical due to its potential to allow remote attackers to read sensitive information.
How do I fix CVE-2018-0207?
To fix CVE-2018-0207, update your Cisco Secure Access Control Server to version 5.8 patch 9 or later.
What causes the CVE-2018-0207 vulnerability?
CVE-2018-0207 is caused by improper handling of XML External Entities in the web-based user interface of the Cisco Secure Access Control Server.
Who is affected by CVE-2018-0207?
CVE-2018-0207 affects users of Cisco Secure Access Control Server versions prior to 5.8 patch 9.
Can CVE-2018-0207 be exploited remotely?
Yes, CVE-2018-0207 can be exploited remotely by unauthenticated attackers.